Microsoft-Windows-WebIO
Event ID 1: ApiObject: WebInitialize completed successfully (ApiVersion ApiVersion) (Flags Flags) -> (API Handle = ApiHandle).
#Message #
Fields #
| Name | Description |
|---|---|
ApiObject Pointer | |
ApiHandle UInt64 | |
ApiVersion UInt64 | |
Flags UInt64 | |
Error UInt32 |
Example Event #
{
"system": {
"channel": "Microsoft-Windows-WebIO/Diagnostic",
"computer": "10.2.10.21",
"correlation": {},
"event_id": 1,
"event_record_id": 0,
"event_source_name": "",
"execution": {
"process_id": 9228,
"thread_id": 10624
},
"guid": "",
"keywords": 0,
"level": 4,
"opcode": 0,
"provider": "Microsoft-Windows-WebIO",
"security": {
"user_id": ""
},
"task": 0,
"time_created": "2026-07-22 01:49:19.855Z",
"version": 0
},
"event_data": {
"ApiHandle": 18374686501414895617,
"ApiObject": "0x2D0918AAD00",
"ApiVersion": 281474976776192,
"Error": 0,
"Flags": 0
},
"message": ""
}
Event ID 2: WebInitialize failed with an error = Error (ApiVersion ApiVersion) (Flags Flags).
#Event ID 3: ApiObject WebTerminate completed successfully.
#Description
ApiObject WebTerminate completed successfully. (Handle ApiHandle) (Flags Flags).
Message #
Fields #
| Name | Description |
|---|---|
ApiObject Pointer | |
ApiHandle UInt64 | |
Flags UInt64 | |
Error UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-WebIO",
"guid": "{50b3e73c-9370-461d-bb9f-26f32d68887d}",
"event_source_name": "",
"event_id": 3,
"version": 0,
"level": 4,
"task": 112,
"opcode": 0,
"keywords": "0x8000000000000001",
"time_created": "2026-07-19T03:58:55.978717700+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "F9F7D40F-7FEA-0000-A636-D303BC32EC1F"
},
"execution": {
"process_id": 12988,
"thread_id": 8172
},
"channel": "Microsoft-Windows-WebIO/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"ApiObject": "0x1858B4FB050",
"ApiHandle": "0xFF00000610000001",
"Flags": "0x0",
"Error": "0x0"
},
"message": "0x1858B4FB050 WebTerminate completed successfully. (Handle 0xFF00000610000001) (Flags 0x0)"
}
Event ID 4: ApiObject WebTerminate failed with an error = Error.
#Event ID 5: Session: WebCreateSession completed successfully.
#Description
Session: WebCreateSession completed successfully. (ApiHandle ApiObject[ApiHandle]) (Flags: Flags) -> (Session Handle: SessionHandle).
Message #
Fields #
| Name | Description |
|---|---|
ApiObject Pointer | |
ApiHandle UInt64 | |
Session Pointer | |
SessionHandle UInt64 | |
Flags UInt64 | |
Error UInt32 |
Example Event #
{
"system": {
"channel": "Microsoft-Windows-WebIO/Diagnostic",
"computer": "10.2.10.21",
"correlation": {},
"event_id": 5,
"event_record_id": 0,
"event_source_name": "",
"execution": {
"process_id": 9228,
"thread_id": 10624
},
"guid": "",
"keywords": 0,
"level": 4,
"opcode": 0,
"provider": "Microsoft-Windows-WebIO",
"security": {
"user_id": ""
},
"task": 0,
"time_created": "2026-07-22 01:49:19.855Z",
"version": 0
},
"event_data": {
"ApiHandle": 18374686501414895617,
"ApiObject": "0x2D0918AAD00",
"Error": 0,
"Flags": 0,
"Session": "0x2D0FA213370",
"SessionHandle": 18302628907645403137
},
"message": ""
}
Event ID 6: ApiObject: WebCreateSession failed with an error = Error.
#Event ID 7: ApiObject: WebCloseSession called (Handle ApiHandle) (Flags Flags).
#Message #
Fields #
| Name | Description |
|---|---|
ApiObject Pointer | |
ApiHandle UInt64 | |
Flags UInt64 | |
Error UInt32 |
Example Event #
{
"system": {
"channel": "Microsoft-Windows-WebIO/Diagnostic",
"computer": "10.2.10.21",
"correlation": {},
"event_id": 7,
"event_record_id": 0,
"event_source_name": "",
"execution": {
"process_id": 4236,
"thread_id": 8496
},
"guid": "",
"keywords": 0,
"level": 4,
"opcode": 1,
"provider": "Microsoft-Windows-WebIO",
"security": {
"user_id": ""
},
"task": 0,
"time_created": "2026-07-22 01:49:03.242Z",
"version": 0
},
"event_data": {
"ApiHandle": 18302628937710174209,
"ApiObject": "0x1CE10BA90F0",
"Error": 0,
"Flags": 0
},
"message": ""
}
Event ID 8: ApiObject: WebCloseSession failed with an error = Error.
#Event ID 9: Api(ApiHandle) API called.
#Event ID 10: Api(ApiHandle) API returned successfully.
#Event ID 11: Api(ApiHandle) API failed with an error = Result.
#Event ID 12: Api(ApiHandle) API pending completion.
#Event ID 13: Api(ApiHandle) API completed.
#Event ID 14: Api(ApiHandle) API completed with an error = Result.
#Event ID 15: Request: Set Request Option Option (Handle RequestHandle) (Error Error) (Length Length) (Value Value).
#Message #
Fields #
| Name | Description |
|---|---|
Request Pointer | |
RequestHandle UInt64 | |
Option UInt32 | |
Length UInt32 | |
Value Binary | |
Error UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-WebIO",
"guid": "{50b3e73c-9370-461d-bb9f-26f32d68887d}",
"event_source_name": "",
"event_id": 15,
"version": 0,
"level": 4,
"task": 201,
"opcode": 14,
"keywords": "0x8000004000000001",
"time_created": "2026-07-19T03:58:54.638535100+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "30000002-0006-FC00-500F-468BBC32EC1F"
},
"execution": {
"process_id": 12988,
"thread_id": 8172
},
"channel": "Microsoft-Windows-WebIO/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Request": "0x1858B460F50",
"RequestHandle": "0xFC00000630000002",
"Option": "5",
"Length": "0x4",
"Value": "0x80000000",
"Error": "0x0"
},
"message": "0x1858B460F50: Set Request Option IgnoredServerCertErrors (Handle 0xFC00000630000002) (Error The operation completed successfully.) (Length 0x4) (Value 0x80000000)"
}
Event ID 17: Request: WebCreateHttpRequest completed successfully.
#Description
Request: WebCreateHttpRequest completed successfully. (Session Session[SessionHandle]) (Method Method) (URI URI) (Version VersionMajor.VersionMinor) -> (Request Handle RequestHandle).
Message #
Fields #
| Name | Description |
|---|---|
Request Pointer | |
RequestHandle UInt64 | |
Session Pointer | |
SessionHandle UInt64 | |
Method AnsiString | |
URI UnicodeString | |
VersionMajor UInt16 | |
VersionMinor UInt16 | |
Error UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-WebIO",
"guid": "{50b3e73c-9370-461d-bb9f-26f32d68887d}",
"event_source_name": "",
"event_id": 17,
"version": 0,
"level": 4,
"task": 200,
"opcode": 0,
"keywords": "0x8000004000000001",
"time_created": "2026-07-19T03:58:54.638469300+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "8B457A00-008D-0000-BC32-EC1F007A458B"
},
"execution": {
"process_id": 12988,
"thread_id": 8172
},
"channel": "Microsoft-Windows-WebIO/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Request": "0x1858B460F50",
"RequestHandle": "0xFC00000630000002",
"Session": "0x1858B4F5630",
"SessionHandle": "0xFD00000620000001",
"Method": "HEAD",
"URI": "http://127.0.0.1:18093/catalog",
"VersionMajor": "0x1",
"VersionMinor": "0x1",
"Error": "0x0"
},
"message": "0x1858B460F50: WebCreateHttpRequest completed successfully. (Session 0x1858B4F5630[0xFD00000620000001]) (Method HEAD) (URI http://127.0.0.1:18093/catalog) (Version 0x1.0x1) -> (Request Handle 0xFC00000630000002)"
}
Event ID 18: Session: WebCreateHttpRequest failed with error: Error.
#Description
Session: WebCreateHttpRequest failed with error: Error. (Session Session[SessionHandle]) (Method Method) (URI URI) (Version VersionMajor.VersionMinor).
Message #
Fields #
| Name | Description |
|---|---|
Request Pointer | |
RequestHandle UInt64 | |
Session Pointer | |
SessionHandle UInt64 | |
Method AnsiString | |
URI UnicodeString | |
VersionMajor UInt16 | |
VersionMinor UInt16 | |
Error UInt32 |
Event ID 19: ApiObject: WebCloseHttpRequest called (Handle ApiHandle) (Flags Flags).
#Message #
Fields #
| Name | Description |
|---|---|
ApiObject Pointer | |
ApiHandle UInt64 | |
Flags UInt64 | |
Error UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-WebIO",
"guid": "{50b3e73c-9370-461d-bb9f-26f32d68887d}",
"event_source_name": "",
"event_id": 19,
"version": 0,
"level": 4,
"task": 202,
"opcode": 1,
"keywords": "0x8000000000000001",
"time_created": "2026-07-19T03:58:56.684911500+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "F9F6D5AE-7FEC-0000-6539-D303BC32F416"
},
"execution": {
"process_id": 12988,
"thread_id": 5876
},
"channel": "Microsoft-Windows-WebIO/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"ApiObject": "0x1858B460F50",
"ApiHandle": "0xFC00000630000002",
"Flags": "0x0",
"Error": "0x0"
},
"message": "0x1858B460F50: WebCloseHttpRequest called (Handle 0xFC00000630000002) (Flags 0x0)"
}
Event ID 20: ApiObject WebCloseHttpRequest failed with an error = Error.
#Event ID 21: Synchronous API Event Handle Signall (Event Event) (Error Error) (Information Information).
#Event ID 22: Synchronous API Event Handle Wait Completed (Handle Handle) (Event Event) (Error Error) (Information Information).
#Event ID 23: Request: WebSetHttpRequestInformationRoutine completed successfully.
#Description
Request: WebSetHttpRequestInformationRoutine completed successfully. (Handle RequestHandle) (Flags Flags) (InformationRoutine InformationRoutine) (InformationContext InformationContext).
Message #
Fields #
| Name | Description |
|---|---|
Request Pointer | |
RequestHandle UInt64 | |
Flags UInt32 | |
InformationRoutine Pointer | |
InformationContext Pointer | |
Error UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-WebIO",
"guid": "{50b3e73c-9370-461d-bb9f-26f32d68887d}",
"event_source_name": "",
"event_id": 23,
"version": 0,
"level": 4,
"task": 201,
"opcode": 14,
"keywords": "0x8000004000000001",
"time_created": "2026-07-19T03:58:54.638494300+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "30000002-0006-FC00-500F-468BBC32EC1F"
},
"execution": {
"process_id": 12988,
"thread_id": 8172
},
"channel": "Microsoft-Windows-WebIO/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Request": "0x1858B460F50",
"RequestHandle": "0xFC00000630000002",
"Flags": "0x80000000",
"InformationRoutine": "0x7FF8FD6AF360",
"InformationContext": "0x1858D13B040",
"Error": "0x0"
},
"message": "0x1858B460F50: WebSetHttpRequestInformationRoutine completed successfully. (Handle 0xFC00000630000002) (Flags 0x80000000) (InformationRoutine 0x7FF8FD6AF360) (InformationContext 0x1858D13B040)"
}
Event ID 24: Request: WebSetHttpRequestInformationRoutine failed with an error = Error.
#Description
Request: WebSetHttpRequestInformationRoutine failed with an error = Error. (Handle RequestHandle) (Flags Flags) (InformationRoutine InformationRoutine) (InformationContext InformationContext).
Message #
Fields #
| Name | Description |
|---|---|
Request Pointer | |
RequestHandle UInt64 | |
Flags UInt32 | |
InformationRoutine Pointer | |
InformationContext Pointer | |
Error UInt32 |
Event ID 25: Request: WebRemoveHttpRequestInformationRoutine completed successfully.
#Description
Request: WebRemoveHttpRequestInformationRoutine completed successfully. (Handle RequestHandle) (Flags Flags).
Message #
Fields #
| Name | Description |
|---|---|
Request Pointer | |
RequestHandle UInt64 | |
Flags UInt32 | |
InformationRoutine Pointer | |
InformationContext Pointer | |
Error UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-WebIO",
"guid": "{50b3e73c-9370-461d-bb9f-26f32d68887d}",
"event_source_name": "",
"event_id": 25,
"version": 0,
"level": 4,
"task": 201,
"opcode": 14,
"keywords": "0x8000004000000001",
"time_created": "2026-07-19T03:58:56.684790800+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "30000002-0006-FC00-500F-468BBC32EC1F"
},
"execution": {
"process_id": 12988,
"thread_id": 5876
},
"channel": "Microsoft-Windows-WebIO/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Request": "0x1858B460F50",
"RequestHandle": "0xFC00000630000002",
"Flags": "0x0",
"InformationRoutine": "0x7FF8FD6AF360",
"InformationContext": "0x1858D13B040",
"Error": "0x0"
},
"message": "0x1858B460F50: WebRemoveHttpRequestInformationRoutine completed successfully. (Handle 0xFC00000630000002) (Flags 0x0)"
}
Event ID 26: Request: WebRemoveHttpRequestInformationRoutine failed with an error = Error.
#Event ID 27: Request: Indicating informational callback to request.
#Description
Request: Indicating informational callback to request. (PendingCount PendingCount) (InformationRoutine InformationRoutine) (InformationContext InformationContext) (Type Type) (Information Information) (InformationLength InformationLength.
Message #
Fields #
| Name | Description |
|---|---|
Request Pointer | |
PendingCount UInt32 | |
InformationRoutine Pointer | |
InformationContext Pointer | |
Type UInt32 | |
Information Pointer | |
InformationLength UInt64 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-WebIO",
"guid": "{50b3e73c-9370-461d-bb9f-26f32d68887d}",
"event_source_name": "",
"event_id": 27,
"version": 0,
"level": 4,
"task": 434,
"opcode": 0,
"keywords": "0x8000000000000001",
"time_created": "2026-07-19T03:58:54.639208100+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "30000002-0006-FC00-500F-468BBC32EC1F"
},
"execution": {
"process_id": 12988,
"thread_id": 8172
},
"channel": "Microsoft-Windows-WebIO/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Request": "0x1858B460F50",
"PendingCount": "0x2",
"InformationRoutine": "0x7FF8FD6AF360",
"InformationContext": "0x1858D13B040",
"Type": "0x4001",
"Information": "0x1858D138486",
"InformationLength": "0x14"
},
"message": "0x1858B460F50: Indicating informational callback to request. (PendingCount 0x2) (InformationRoutine 0x7FF8FD6AF360) (InformationContext 0x1858D13B040) (Type 0x4001) (Information 0x1858D138486) (InformationLength 0x14"
}
Event ID 28: Request: Informational callback to request complete.
#Description
Request: Informational callback to request complete. (PendingCount PendingCount) (InformationRoutine InformationRoutine) (InformationContext InformationContext) (Type Type) (Information Information) (InformationLength InformationLength.
Message #
Fields #
| Name | Description |
|---|---|
Request Pointer | |
PendingCount UInt32 | |
InformationRoutine Pointer | |
InformationContext Pointer | |
Type UInt32 | |
Information Pointer | |
InformationLength UInt64 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-WebIO",
"guid": "{50b3e73c-9370-461d-bb9f-26f32d68887d}",
"event_source_name": "",
"event_id": 28,
"version": 0,
"level": 4,
"task": 434,
"opcode": 0,
"keywords": "0x8000000000000001",
"time_created": "2026-07-19T03:58:54.639222800+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "30000002-0006-FC00-500F-468BBC32EC1F"
},
"execution": {
"process_id": 12988,
"thread_id": 8172
},
"channel": "Microsoft-Windows-WebIO/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Request": "0x1858B460F50",
"PendingCount": "0x2",
"InformationRoutine": "0x7FF8FD6AF360",
"InformationContext": "0x1858D13B040",
"Type": "0x4001",
"Information": "0x1858D138486",
"InformationLength": "0x14"
},
"message": "0x1858B460F50: Informational callback to request complete. (PendingCount 0x2) (InformationRoutine 0x7FF8FD6AF360) (InformationContext 0x1858D13B040) (Type 0x4001) (Information 0x1858D138486) (InformationLength 0x14"
}
Event ID 29: ApiObject: WebCloseSession completed successfully.
#Description
ApiObject: WebCloseSession completed successfully. (Handle ApiHandle) (Flags Flags).
Message #
Fields #
| Name | Description |
|---|---|
ApiObject Pointer | |
ApiHandle UInt64 | |
Flags UInt64 | |
Error UInt32 |
Example Event #
{
"system": {
"channel": "Microsoft-Windows-WebIO/Diagnostic",
"computer": "10.2.10.21",
"correlation": {},
"event_id": 29,
"event_record_id": 0,
"event_source_name": "",
"execution": {
"process_id": 4236,
"thread_id": 8496
},
"guid": "",
"keywords": 0,
"level": 4,
"opcode": 2,
"provider": "Microsoft-Windows-WebIO",
"security": {
"user_id": ""
},
"task": 0,
"time_created": "2026-07-22 01:49:03.242Z",
"version": 0
},
"event_data": {
"ApiHandle": 18302628937710174209,
"ApiObject": "0x1CE10BA90F0",
"Error": 0,
"Flags": 0
},
"message": ""
}
Event ID 30: ApiObject: WebCloseHttpRequest completed sucessfully error = Error.
#Description
ApiObject: WebCloseHttpRequest completed sucessfully error = Error. (Handle ApiHandle) (Flags Flags).
Message #
Fields #
| Name | Description |
|---|---|
ApiObject Pointer | |
ApiHandle UInt64 | |
Flags UInt64 | |
Error UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-WebIO",
"guid": "{50b3e73c-9370-461d-bb9f-26f32d68887d}",
"event_source_name": "",
"event_id": 30,
"version": 0,
"level": 4,
"task": 202,
"opcode": 2,
"keywords": "0x8000000000000001",
"time_created": "2026-07-19T03:58:56.685348800+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "F9F6D5AE-7FEC-0000-6539-D303BC32F416"
},
"execution": {
"process_id": 12988,
"thread_id": 5876
},
"channel": "Microsoft-Windows-WebIO/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"ApiObject": "0x1858B460F50",
"ApiHandle": "0xFC00000630000002",
"Flags": "0x0",
"Error": "0x0"
},
"message": "0x1858B460F50: WebCloseHttpRequest completed sucessfully error = The operation completed successfully.. (Handle 0xFC00000630000002) (Flags 0x0)"
}
Event ID 100: Request: Sending Headers: Headers.
#Message #
Fields #
| Name | Description |
|---|---|
Request Pointer | |
Length UInt16 | |
Headers AnsiString |
Example Event #
{
"system": {
"channel": "Microsoft-Windows-WebIO/Diagnostic",
"computer": "10.2.10.21",
"correlation": {},
"event_id": 100,
"event_record_id": 0,
"event_source_name": "",
"execution": {
"process_id": 9228,
"thread_id": 13156
},
"guid": "",
"keywords": 0,
"level": 4,
"opcode": 0,
"provider": "Microsoft-Windows-WebIO",
"security": {
"user_id": ""
},
"task": 0,
"time_created": "2026-07-22 01:49:20.176Z",
"version": 0
},
"event_data": {
"Headers": "揑\u0002\u0000\u0000揑\u0002\u0000\u0000\u0007\u0000\u0000\u0000\u0004\u0000\u0000\u0000揑\u0002\u0000\u0000揑\u0002\u0000\u0000\u0005\u0000\u0000\u0000 \u0000\u0000\u0000\u0018珑\u0002\u0000\u0000\"珑\u0002\u0000\u0000\n\u0000\u0000\u0000\u001a\u0000\u0000\u0000<珑\u0002\u0000\u0000C珑\u0002\u0000\u0000\u0007\u0000\u0000\u0000\u0005\u0000\u0000\u0000H珑\u0002\u0000\u0000U珑\u0002\u0000\u0000\r\u0000\u0000\u0000\b\u0000\u0000\u0000]珑\u0002\u0000\u0000c珑\u0002\u0000\u0000\u0006\u0000\u0000\u0000\b\u0000\u0000\u0000k珑\u0002\u0000\u0000w珑\u0002\u0000\u0000\f\u0000\u0000\u0000\u0017\u0000\u0000\u0000珑\u0002\u0000\u0000珑\u0002\u0000\u0000\u000f\u0000\u0000\u0000\u0006\u0000\u0000\u0000珑\u0002\u0000\u0000珑\u0002\u0000\u0000\n\u0000\u0000\u0000;\u0000\u0000\u0000珑\u0002\u0000\u0000珑\u0002\u0000\u0000\n\u0000\u0000\u0000Y\u0000\u0000\u0000K菑\u0002\u0000\u0000P菑\u0002\u0000\u0000\u0005\u0000\u0000\u0000\u001a\u0000\u0000\u0000j菑\u0002\u0000\u0000x菑\u0002\u0000\u0000\u000e\u0000\u0000\u0000\u0003\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000:methodPOST:path/v6/ClientWebService/client.asmx:authorityfe2cr.update.microsoft.com:schemehttpscache-controlno-cachepragmano-cachecontent-typetext/xml; charset=utf-8accept-encodingxpressuser-agentWindows-Update-Agent/1407.2508.19012.0 Client-Protocol/2.90soapaction\"http://www.microsoft.com/SoftwareDistribution/Server/ClientWebService/StartCategoryScan\"ms-cvVWio2qJH/0SQYyTv.1.0.0.2.1content-length538",
"Length": 715,
"Request": "0x2D09186A540"
},
"message": ""
}
Event ID 101: Request: Received Headers: Headers.
#Message #
Fields #
| Name | Description |
|---|---|
Request Pointer | |
Length UInt16 | |
Headers AnsiString |
Example Event #
{
"system": {
"channel": "Microsoft-Windows-WebIO/Diagnostic",
"computer": "10.2.10.21",
"correlation": {},
"event_id": 101,
"event_record_id": 0,
"event_source_name": "",
"execution": {
"process_id": 4236,
"thread_id": 12820
},
"guid": "",
"keywords": 0,
"level": 4,
"opcode": 0,
"provider": "Microsoft-Windows-WebIO",
"security": {
"user_id": ""
},
"task": 0,
"time_created": "2026-07-22 01:49:03.235Z",
"version": 0
},
"event_data": {
"Headers": "HTTP/1.1 200\r\ncontent-length: 11\r\ncontent-type: application/json\r\nserver: Microsoft-HTTPAPI/2.0\r\nstrict-transport-security: max-age=31536000\r\ntime-delta-millis: 2930\r\naccess-control-allow-headers: time-delta-millis\r\naccess-control-allow-methods: POST\r\naccess-control-allow-credentials: true\r\naccess-control-allow-origin: *\r\naccess-control-expose-headers: time-delta-millis\r\ndate: Wed, 22 Jul 2026 01:49:02 GMT\r\n\r\n",
"Length": 413,
"Request": "0x1CE0F728280"
},
"message": ""
}
Event ID 104: Request: Acquired a connection slot (ConnMgr: ConnMgr), (Connection: Connection).
#Message #
Fields #
| Name | Description |
|---|---|
Request Pointer | |
ConnMgr Pointer | |
Connection Pointer |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-WebIO",
"guid": "{50b3e73c-9370-461d-bb9f-26f32d68887d}",
"event_source_name": "",
"event_id": 104,
"version": 0,
"level": 4,
"task": 410,
"opcode": 2,
"keywords": "0x8000000000000000",
"time_created": "2026-07-19T03:58:54.639100400+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "30000002-0006-FC00-500F-468BBC32EC1F"
},
"execution": {
"process_id": 12988,
"thread_id": 8172
},
"channel": "Microsoft-Windows-WebIO/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Request": "0x1858B460F50",
"ConnMgr": "0x1858D0E73E0",
"Connection": "0x1858D0863A0"
},
"message": "0x1858B460F50: Acquired a connection slot (ConnMgr: 0x1858D0E73E0), (Connection: 0x1858D0863A0)"
}
Event ID 105: Request: Request on Endpoint (Server Endpoint: ServerEndpoint) (Proxy Endpoint: ProxyEndpoint) (Connection Manager: ConnectionManager).
#Message #
Fields #
| Name | Description |
|---|---|
Request Pointer | |
ServerEndpoint Pointer | |
ProxyEndpoint Pointer | |
ConnectionManager Pointer |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-WebIO",
"guid": "{50b3e73c-9370-461d-bb9f-26f32d68887d}",
"event_source_name": "",
"event_id": 105,
"version": 0,
"level": 4,
"task": 403,
"opcode": 0,
"keywords": "0x8000000000000000",
"time_created": "2026-07-19T03:58:54.639042000+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "30000002-0006-FC00-500F-468BBC32EC1F"
},
"execution": {
"process_id": 12988,
"thread_id": 8172
},
"channel": "Microsoft-Windows-WebIO/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Request": "0x1858B460F50",
"ServerEndpoint": "0x1858D0EF310",
"ProxyEndpoint": "0x0",
"ConnectionManager": "0x1858D0E73E0"
},
"message": "0x1858B460F50: Request on Endpoint (Server Endpoint: 0x1858D0EF310) (Proxy Endpoint: 0x0) (Connection Manager: 0x1858D0E73E0)"
}
Event ID 106: Request: Request Message Generated (DataChunk DataChunks[Length]).
#Message #
Fields #
| Name | Description |
|---|---|
Request Pointer | |
DataChunks Pointer | |
Length UInt64 |
Example Event #
{
"system": {
"channel": "Microsoft-Windows-WebIO/Diagnostic",
"computer": "10.2.10.21",
"correlation": {},
"event_id": 106,
"event_record_id": 0,
"event_source_name": "",
"execution": {
"process_id": 9228,
"thread_id": 13156
},
"guid": "",
"keywords": 0,
"level": 4,
"opcode": 2,
"provider": "Microsoft-Windows-WebIO",
"security": {
"user_id": ""
},
"task": 0,
"time_created": "2026-07-22 01:49:20.176Z",
"version": 0
},
"event_data": {
"DataChunks": "0x2D0F84E85B0",
"Length": 715,
"Request": "0x2D09186A540"
},
"message": ""
}
Event ID 107: Request: WebSendHttpRequestEntity (Handle: RequestHandle) (Flags: Flags) (DataChunks DataChunks [DataChunkCount]) CompletionContext (CompletionContext).
#Message #
Fields #
| Name | Description |
|---|---|
Request Pointer | |
RequestHandle UInt64 | |
Flags UInt32 | |
DataChunks Pointer | |
DataChunkCount UInt32 | |
CompletionContext Pointer | |
Error UInt32 |
Example Event #
{
"system": {
"channel": "Microsoft-Windows-WebIO/Diagnostic",
"computer": "10.2.10.21",
"correlation": {},
"event_id": 107,
"event_record_id": 0,
"event_source_name": "",
"execution": {
"process_id": 4236,
"thread_id": 8496
},
"guid": "",
"keywords": 0,
"level": 4,
"opcode": 1,
"provider": "Microsoft-Windows-WebIO",
"security": {
"user_id": ""
},
"task": 0,
"time_created": "2026-07-22 01:49:49.530Z",
"version": 0
},
"event_data": {
"CompletionContext": "0x1CE13D19640",
"DataChunkCount": 1,
"DataChunks": "0x1CE119FF720",
"Error": 0,
"Flags": 0,
"Request": "0x1CE0F72DEC0",
"RequestHandle": 18230571300991008771
},
"message": ""
}
Event ID 108: Request: WebSendHttpRequestEntity Inline Completion (Handle: RequestHandle) (Error: Error) (Flags: Flags) (DataChunks DataChunks [DataChunkCount]) CompletionContext (CompletionContext).
#Message #
Fields #
| Name | Description |
|---|---|
Request Pointer | |
RequestHandle UInt64 | |
Flags UInt32 | |
DataChunks Pointer | |
DataChunkCount UInt32 | |
CompletionContext Pointer | |
Error UInt32 |
Example Event #
{
"system": {
"channel": "Microsoft-Windows-WebIO/Diagnostic",
"computer": "10.2.10.21",
"correlation": {},
"event_id": 108,
"event_record_id": 0,
"event_source_name": "",
"execution": {
"process_id": 4236,
"thread_id": 8496
},
"guid": "",
"keywords": 0,
"level": 4,
"opcode": 2,
"provider": "Microsoft-Windows-WebIO",
"security": {
"user_id": ""
},
"task": 0,
"time_created": "2026-07-22 01:49:49.531Z",
"version": 0
},
"event_data": {
"CompletionContext": "0x1CE13D19640",
"DataChunkCount": 1,
"DataChunks": "0x1CE119FF720",
"Error": 997,
"Flags": 0,
"Request": "0x1CE0F72DEC0",
"RequestHandle": 18230571300991008771
},
"message": ""
}
Event ID 109: Request: HTTP Queuing Entity for Sending (DataChunks DataChunks) (ChunkLength TotalChunkLength) (IsEntity IsEntity).
#Description
Request: HTTP Queuing Entity for Sending (DataChunks DataChunks) (ChunkLength TotalChunkLength) (IsEntity IsEntity) (All Entity Posted? RequestEntityComplete).
Message #
Fields #
| Name | Description |
|---|---|
Request Pointer | |
DataChunks Pointer | |
TotalChunkLength UInt64 | |
IsEntity Boolean | |
RequestEntityComplete Boolean |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-WebIO",
"guid": "{50b3e73c-9370-461d-bb9f-26f32d68887d}",
"event_source_name": "",
"event_id": 109,
"version": 0,
"level": 4,
"task": 406,
"opcode": 11,
"keywords": "0x8000000100000000",
"time_created": "2026-07-19T03:58:54.638948900+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "30000002-0006-FC00-500F-468BBC32EC1F"
},
"execution": {
"process_id": 12988,
"thread_id": 8172
},
"channel": "Microsoft-Windows-WebIO/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Request": "0x1858B460F50",
"DataChunks": "0x1858D0EFF00",
"TotalChunkLength": "0x0",
"IsEntity": "false",
"RequestEntityComplete": "true"
},
"message": "0x1858B460F50: HTTP Queuing Entity for Sending (DataChunks 0x1858D0EFF00) (ChunkLength 0x0) (IsEntity false) (All Entity Posted? true)"
}
Event ID 110: Request: HTTP Sending Entity (Connection: Connection) (DataChunks DataChunks) (PendingSendCount PendingSendCount).
#Description
Request: HTTP Sending Entity (Connection: Connection) (DataChunks DataChunks) (PendingSendCount PendingSendCount) (LastSend? LastSend).
Message #
Fields #
| Name | Description |
|---|---|
Request Pointer | |
Connection Pointer | |
DataChunks Pointer | |
PendingSendCount UInt32 | |
LastSend Boolean | |
Error UInt32 |
Example Event #
{
"system": {
"channel": "Microsoft-Windows-WebIO/Diagnostic",
"computer": "10.2.10.21",
"correlation": {},
"event_id": 110,
"event_record_id": 0,
"event_source_name": "",
"execution": {
"process_id": 9228,
"thread_id": 13156
},
"guid": "",
"keywords": 0,
"level": 4,
"opcode": 1,
"provider": "Microsoft-Windows-WebIO",
"security": {
"user_id": ""
},
"task": 0,
"time_created": "2026-07-22 01:49:20.176Z",
"version": 0
},
"event_data": {
"Connection": "0x2D090AFE040",
"DataChunks": "0x2D0F84E9960",
"Error": 0,
"LastSend": true,
"PendingSendCount": 2,
"Request": "0x2D09186A540"
},
"message": ""
}
Event ID 111: Request: HTTP Send Entity Details (Connection: Connection) (DataChunks DataChunks) (Index Index) (Buffer Buffer [Length]) Data: Data.
#Message #
Fields #
| Name | Description |
|---|---|
Request Pointer | |
Connection Pointer | |
DataChunks Pointer | |
Index UInt32 | |
Buffer Pointer | |
Length UInt32 | |
Data Binary |
Example Event #
{
"system": {
"channel": "Microsoft-Windows-WebIO/Diagnostic",
"computer": "10.2.10.21",
"correlation": {},
"event_id": 111,
"event_record_id": 0,
"event_source_name": "",
"execution": {
"process_id": 9228,
"thread_id": 13156
},
"guid": "",
"keywords": 0,
"level": 4,
"opcode": 0,
"provider": "Microsoft-Windows-WebIO",
"security": {
"user_id": ""
},
"task": 0,
"time_created": "2026-07-22 01:49:20.176Z",
"version": 0
},
"event_data": {
"Buffer": "0x2D0FA27CB40",
"Connection": "0x2D090AFE040",
"Data": "3C733A456E76656C6F706520786D6C6E733A733D22687474703A2F2F736368656D61732E786D6C736F61702E6F72672F736F61702F656E76656C6F70652F223E3C733A426F64793E3C537461727443617465676F72795363616E20786D6C6E733D22687474703A2F2F7777772E6D6963726F736F66742E636F6D2F536F667477617265446973747269627574696F6E2F5365727665722F436C69656E7457656253657276696365223E3C72657175657374656443617465676F726965733E3C43617465676F727952656C6174696F6E736869703E3C496E6465784F66416E6447726F75703E303C2F496E6465784F66416E6447726F75703E3C43617465676F727949643E38633366636338342D373431302D346139352D386238392D6131363661303139303438363C2F43617465676F727949643E3C2F43617465676F727952656C6174696F6E736869703E3C43617465676F727952656C6174696F6E736869703E3C496E6465784F66416E6447726F75703E303C2F496E6465784F66416E6447726F75703E3C43617465676F727949643E65303738393632382D636530382D343433372D626537342D3234393562383432663433623C2F43617465676F727949643E3C2F43617465676F727952656C6174696F6E736869703E3C2F72657175657374656443617465676F726965733E3C2F537461727443617465676F72795363616E3E3C2F733A426F64793E3C2F733A456E76656C6F70653E",
"DataChunks": "0x2D0F84E9960",
"Index": 0,
"Length": 538,
"Request": "0x2D09186A540"
},
"message": ""
}
Event ID 112: Request: HTTP Sending Entity Complete (Error Error) (Connection: Connection) (DataChunks DataChunks) (PendingSendCount PendingSendCount).
#Description
Request: HTTP Sending Entity Complete (Error Error) (Connection: Connection) (DataChunks DataChunks) (PendingSendCount PendingSendCount) (LastSend? LastSend).
Message #
Fields #
| Name | Description |
|---|---|
Request Pointer | |
Connection Pointer | |
DataChunks Pointer | |
PendingSendCount UInt32 | |
LastSend Boolean | |
Error UInt32 |
Example Event #
{
"system": {
"channel": "Microsoft-Windows-WebIO/Diagnostic",
"computer": "10.2.10.21",
"correlation": {},
"event_id": 112,
"event_record_id": 0,
"event_source_name": "",
"execution": {
"process_id": 9228,
"thread_id": 13156
},
"guid": "",
"keywords": 0,
"level": 4,
"opcode": 2,
"provider": "Microsoft-Windows-WebIO",
"security": {
"user_id": ""
},
"task": 0,
"time_created": "2026-07-22 01:49:20.178Z",
"version": 0
},
"event_data": {
"Connection": "0x0",
"DataChunks": "0x2D0F84E9960",
"Error": 0,
"LastSend": false,
"PendingSendCount": 0,
"Request": "0x2D09186A540"
},
"message": ""
}
Event ID 113: Request: Completing WebSendHttpRequest(Entity) (DataChunks DataChunks) (Error Error) (CompletionContext CompletionContext) (CompletionInformation CompletionInformation).
#Message #
Fields #
| Name | Description |
|---|---|
Request Pointer | |
DataChunks Pointer | |
Error UInt32 | |
CompletionContext Pointer | |
CompletionInformation UInt64 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-WebIO",
"guid": "{50b3e73c-9370-461d-bb9f-26f32d68887d}",
"event_source_name": "",
"event_id": 113,
"version": 0,
"level": 4,
"task": 407,
"opcode": 1,
"keywords": "0x8000000100000001",
"time_created": "2026-07-19T03:58:56.684688500+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "30000002-0006-FC00-500F-468BBC32EC1F"
},
"execution": {
"process_id": 12988,
"thread_id": 5876
},
"channel": "Microsoft-Windows-WebIO/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Request": "0x1858B460F50",
"DataChunks": "0x1858D0EFF00",
"Error": "0x274D",
"CompletionContext": "0x1858D13B150",
"CompletionInformation": "0x0"
},
"message": "0x1858B460F50: Completing WebSendHttpRequest(Entity) (DataChunks 0x1858D0EFF00) (Error No connection could be made because the target machine actively refused it.) (CompletionContext 0x1858D13B150) (CompletionInformation 0x0)"
}
Event ID 114: Request: Completing WebSendHttpRequest(Entity) Complete (DataChunks DataChunks).
#Message #
Fields #
| Name | Description |
|---|---|
Request Pointer | |
DataChunks Pointer | |
Error UInt32 | |
CompletionContext Pointer | |
CompletionInformation UInt64 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-WebIO",
"guid": "{50b3e73c-9370-461d-bb9f-26f32d68887d}",
"event_source_name": "",
"event_id": 114,
"version": 0,
"level": 4,
"task": 407,
"opcode": 2,
"keywords": "0x8000000100000001",
"time_created": "2026-07-19T03:58:56.684744700+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "30000002-0006-FC00-500F-468BBC32EC1F"
},
"execution": {
"process_id": 12988,
"thread_id": 5876
},
"channel": "Microsoft-Windows-WebIO/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Request": "0x1858B460F50",
"DataChunks": "0x1858D0EFF00",
"Error": "0x274D",
"CompletionContext": "0x1858D13B150",
"CompletionInformation": "0x0"
},
"message": "0x1858B460F50: Completing WebSendHttpRequest(Entity) Complete (DataChunks 0x1858D0EFF00)"
}
Event ID 115: Request: WebHttpReceiveEntityBody (Handle: RequestHandle) (Flags: Flags) (DataChunks DataChunks [DataChunkCount]) CompletionContext (CompletionContext).
#Message #
Fields #
| Name | Description |
|---|---|
Request Pointer | |
RequestHandle UInt64 | |
Flags UInt32 | |
DataChunks Pointer | |
DataChunkCount UInt32 | |
CompletionContext Pointer | |
Error UInt32 |
Example Event #
{
"system": {
"channel": "Microsoft-Windows-WebIO/Diagnostic",
"computer": "10.2.10.21",
"correlation": {},
"event_id": 115,
"event_record_id": 0,
"event_source_name": "",
"execution": {
"process_id": 4236,
"thread_id": 12820
},
"guid": "",
"keywords": 0,
"level": 4,
"opcode": 1,
"provider": "Microsoft-Windows-WebIO",
"security": {
"user_id": ""
},
"task": 0,
"time_created": "2026-07-22 01:49:03.236Z",
"version": 0
},
"event_data": {
"CompletionContext": "0x1CE140D42A0",
"DataChunkCount": 1,
"DataChunks": "0x1CE140D4340",
"Error": 0,
"Flags": 1,
"Request": "0x1CE0F728280",
"RequestHandle": 18230571296696041478
},
"message": ""
}
Event ID 116: Request: WebHttpReceiveEntityBody Inline Completion (Handle: RequestHandle) (Error: Error) (Flags: Flags) (DataChunks DataChunks [DataChunkCount]) CompletionContext (CompletionContext).
#Event ID 117: Request: Completing WebHttpReceiveEntityBody (DataChunks DataChunks) (Error Error) (CompletionContext CompletionContext) (CompletionInformation CompletionInformation).
#Message #
Fields #
| Name | Description |
|---|---|
Request Pointer | |
DataChunks Pointer | |
Error UInt32 | |
CompletionContext Pointer | |
CompletionInformation UInt64 |
Example Event #
{
"system": {
"channel": "Microsoft-Windows-WebIO/Diagnostic",
"computer": "10.2.10.21",
"correlation": {},
"event_id": 117,
"event_record_id": 0,
"event_source_name": "",
"execution": {
"process_id": 9228,
"thread_id": 10624
},
"guid": "",
"keywords": 0,
"level": 4,
"opcode": 1,
"provider": "Microsoft-Windows-WebIO",
"security": {
"user_id": ""
},
"task": 0,
"time_created": "2026-07-22 01:49:20.416Z",
"version": 0
},
"event_data": {
"CompletionContext": "0x2D0FA284B30",
"CompletionInformation": 256,
"DataChunks": "0x2D0FA6AC438",
"Error": 0,
"Request": "0x2D09186A540"
},
"message": ""
}
Event ID 118: Request: Completing WebHttpReceiveEntityBody Complete (DataChunks DataChunks).
#Message #
Fields #
| Name | Description |
|---|---|
Request Pointer | |
DataChunks Pointer | |
Error UInt32 | |
CompletionContext Pointer | |
CompletionInformation UInt64 |
Example Event #
{
"system": {
"channel": "Microsoft-Windows-WebIO/Diagnostic",
"computer": "10.2.10.21",
"correlation": {},
"event_id": 118,
"event_record_id": 0,
"event_source_name": "",
"execution": {
"process_id": 9228,
"thread_id": 10624
},
"guid": "",
"keywords": 0,
"level": 4,
"opcode": 2,
"provider": "Microsoft-Windows-WebIO",
"security": {
"user_id": ""
},
"task": 0,
"time_created": "2026-07-22 01:49:20.416Z",
"version": 0
},
"event_data": {
"CompletionContext": "0x2D0FA284B30",
"CompletionInformation": 256,
"DataChunks": "0x2D0FA6AC438",
"Error": 0,
"Request": "0x2D09186A540"
},
"message": ""
}
Event ID 119: Connection: HTTP Connection changing Buffer (OldBuffer OldBuffer [OldBufferLength]) (NewBuffer NewBuffer [NewBufferLength]) (Carryover BufferLengthData).
#Message #
Fields #
| Name | Description |
|---|---|
Connection Pointer | |
OldBuffer Pointer | |
OldBufferLength UInt32 | |
BufferLengthData UInt32 | |
NewBuffer Pointer | |
NewBufferLength UInt32 |
Example Event #
{
"system": {
"channel": "Microsoft-Windows-WebIO/Diagnostic",
"computer": "10.2.10.21",
"correlation": {},
"event_id": 119,
"event_record_id": 0,
"event_source_name": "",
"execution": {
"process_id": 4356,
"thread_id": 3784
},
"guid": "",
"keywords": 0,
"level": 4,
"opcode": 15,
"provider": "Microsoft-Windows-WebIO",
"security": {
"user_id": ""
},
"task": 0,
"time_created": "2026-07-22 02:12:40.406Z",
"version": 0
},
"event_data": {
"BufferLengthData": 0,
"Connection": "0x25AC1880240",
"NewBuffer": "0x25ABFE02040",
"NewBufferLength": 4048,
"OldBuffer": "0x25ABFE03040",
"OldBufferLength": 4048
},
"message": ""
}
Event ID 120: Connection: HTTP Connection Buffer Posting Receive (DataChunks DataChunks) (Buffer: Buffer [BufferLengthConsumed/BufferLengthData/BufferLengthRemaining]).
#Message #
Fields #
| Name | Description |
|---|---|
Connection Pointer | |
DataChunks Pointer | |
Buffer Pointer | |
BufferLengthConsumed UInt32 | |
BufferLengthData UInt32 | |
BufferLengthRemaining UInt32 | |
Error UInt32 | |
Information UInt64 |
Example Event #
{
"system": {
"channel": "Microsoft-Windows-WebIO/Diagnostic",
"computer": "10.2.10.21",
"correlation": {},
"event_id": 120,
"event_record_id": 0,
"event_source_name": "",
"execution": {
"process_id": 4236,
"thread_id": 12820
},
"guid": "",
"keywords": 0,
"level": 4,
"opcode": 1,
"provider": "Microsoft-Windows-WebIO",
"security": {
"user_id": ""
},
"task": 0,
"time_created": "2026-07-22 01:49:03.236Z",
"version": 0
},
"event_data": {
"Buffer": "0x1CE13E3E0B0",
"BufferLengthConsumed": 413,
"BufferLengthData": 0,
"BufferLengthRemaining": 3635,
"Connection": "0x1CE11907080",
"DataChunks": "0x1CE11907428",
"Error": 0,
"Information": 0
},
"message": ""
}
Event ID 121: Connection: HTTP Connection Buffer Completing Receive (DataChunks DataChunks) (Buffer: Buffer [BufferLengthConsumed/BufferLengthData/BufferLengthRemaining]) (Error Error) (CompletionInformation Inf...
#Description
Connection: HTTP Connection Buffer Completing Receive (DataChunks DataChunks) (Buffer: Buffer [BufferLengthConsumed/BufferLengthData/BufferLengthRemaining]) (Error Error) (CompletionInformation Information).
Message #
Fields #
| Name | Description |
|---|---|
Connection Pointer | |
DataChunks Pointer | |
Buffer Pointer | |
BufferLengthConsumed UInt32 | |
BufferLengthData UInt32 | |
BufferLengthRemaining UInt32 | |
Error UInt32 | |
Information UInt64 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-WebIO",
"guid": "{50B3E73C-9370-461D-BB9F-26F32D68887D}",
"event_source_name": "",
"event_id": 121,
"version": 0,
"level": 5,
"task": 415,
"opcode": 2,
"keywords": "0x0000000200000000",
"time_created": "2026-06-02T04:01:52.944+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{EB64A0B3-7FFC-0000-D588-CD01FC2D780D}"
},
"execution": {
"process_id": 11772,
"thread_id": 13132
},
"channel": "ETW Trace",
"computer": "JD-DC01-2022",
"security": {
"user_id": ""
}
},
"event_data": {
"Buffer": "0x23E91026950",
"BufferLengthConsumed": 0,
"BufferLengthData": 0,
"BufferLengthRemaining": 4048,
"Connection": "0x23E900EFC70",
"DataChunks": "0x23E900F0838",
"Error": 995,
"Information": 0
},
"message": "Task.ResponseConnectionBufferReceive"
}
Event ID 122: Connection: HTTP Connection Buffer Receive Details (DataChunks DataChunks) (Length Length) Data: Data.
#Message #
Fields #
| Name | Description |
|---|---|
Connection Pointer | |
DataChunks Pointer | |
Length UInt32 | |
Data Binary |
Example Event #
{
"system": {
"channel": "Microsoft-Windows-WebIO/Diagnostic",
"computer": "10.2.10.21",
"correlation": {},
"event_id": 122,
"event_record_id": 0,
"event_source_name": "",
"execution": {
"process_id": 4236,
"thread_id": 12820
},
"guid": "",
"keywords": 0,
"level": 4,
"opcode": 0,
"provider": "Microsoft-Windows-WebIO",
"security": {
"user_id": ""
},
"task": 0,
"time_created": "2026-07-22 01:49:03.235Z",
"version": 0
},
"event_data": {
"Connection": "0x1CE11907080",
"Data": "485454502F312E31203230300D0A636F6E74656E742D6C656E6774683A2031310D0A636F6E74656E742D747970653A206170706C69636174696F6E2F6A736F6E0D0A7365727665723A204D6963726F736F66742D485454504150492F322E300D0A7374726963742D7472616E73706F72742D73656375726974793A206D61782D6167653D33313533363030300D0A74696D652D64656C74612D6D696C6C69733A20323933300D0A6163636573732D636F6E74726F6C2D616C6C6F772D686561646572733A2074696D652D64656C74612D6D696C6C69730D0A6163636573732D636F6E74726F6C2D616C6C6F772D6D6574686F64733A20504F53540D0A6163636573732D636F6E74726F6C2D616C6C6F772D63726564656E7469616C733A20747275650D0A6163636573732D636F6E74726F6C2D616C6C6F772D6F726967696E3A202A0D0A6163636573732D636F6E74726F6C2D6578706F73652D686561646572733A2074696D652D64656C74612D6D696C6C69730D0A646174653A205765642C203232204A756C20323032362030313A34393A303220474D540D0A0D0A",
"DataChunks": "0x1CE11907428",
"Length": 413
},
"message": ""
}
Event ID 123: Request: HTTP Parser (Connection Connection) (Buffer: Buffer [BufferLengthConsumed/BufferLengthData/BufferLengthRemaining]) (ParserChunk ChunkData [ChunkDataLength]).
#Message #
Fields #
| Name | Description |
|---|---|
Request Pointer | |
Connection Pointer | |
Buffer Pointer | |
BufferLengthConsumed UInt32 | |
BufferLengthData UInt32 | |
BufferLengthRemaining UInt32 | |
ChunkData Pointer | |
ChunkDataLength UInt32 | |
Error UInt32 |
Example Event #
{
"system": {
"channel": "Microsoft-Windows-WebIO/Diagnostic",
"computer": "10.2.10.21",
"correlation": {},
"event_id": 123,
"event_record_id": 0,
"event_source_name": "",
"execution": {
"process_id": 4236,
"thread_id": 12820
},
"guid": "",
"keywords": 0,
"level": 4,
"opcode": 1,
"provider": "Microsoft-Windows-WebIO",
"security": {
"user_id": ""
},
"task": 0,
"time_created": "2026-07-22 01:49:03.235Z",
"version": 0
},
"event_data": {
"Buffer": "0x1CE13E3E0B0",
"BufferLengthConsumed": 0,
"BufferLengthData": 413,
"BufferLengthRemaining": 3635,
"ChunkData": "0x0",
"ChunkDataLength": 0,
"Connection": "0x1CE11907080",
"Error": 0,
"Request": "0x1CE0F728280"
},
"message": ""
}
Event ID 124: Request: HTTP Parser Complete (Connection Connection) (Error Error) (Buffer: Buffer [BufferLengthConsumed/BufferLengthData/BufferLengthRemaining]) (ParserChunk ChunkData [ChunkDataLength]).
#Message #
Fields #
| Name | Description |
|---|---|
Request Pointer | |
Connection Pointer | |
Buffer Pointer | |
BufferLengthConsumed UInt32 | |
BufferLengthData UInt32 | |
BufferLengthRemaining UInt32 | |
ChunkData Pointer | |
ChunkDataLength UInt32 | |
Error UInt32 |
Example Event #
{
"system": {
"channel": "Microsoft-Windows-WebIO/Diagnostic",
"computer": "10.2.10.21",
"correlation": {},
"event_id": 124,
"event_record_id": 0,
"event_source_name": "",
"execution": {
"process_id": 4236,
"thread_id": 12820
},
"guid": "",
"keywords": 0,
"level": 4,
"opcode": 2,
"provider": "Microsoft-Windows-WebIO",
"security": {
"user_id": ""
},
"task": 0,
"time_created": "2026-07-22 01:49:03.235Z",
"version": 0
},
"event_data": {
"Buffer": "0x1CE13E3E0B0",
"BufferLengthConsumed": 413,
"BufferLengthData": 0,
"BufferLengthRemaining": 3635,
"ChunkData": "0x1CE13E3E27D",
"ChunkDataLength": 0,
"Connection": "0x1CE11907080",
"Error": 997,
"Request": "0x1CE0F728280"
},
"message": ""
}
Event ID 125: Request: HTTP Parser Reset (Buffer Buffer) (HttpResponseCode HttpResponseCode).
#Event ID 126: Request: HTTP Receive From Parser (DataChunk DataChunks) (ParserChunk ChunkData [ChunkDataLength]) (Error Error) (Context CompletionContext) (Information CompletionInformation).
#Message #
Fields #
| Name | Description |
|---|---|
Request Pointer | |
DataChunks Pointer | |
ChunkData Pointer | |
ChunkDataLength UInt32 | |
Error UInt32 | |
CompletionContext Pointer | |
CompletionInformation UInt64 |
Example Event #
{
"system": {
"channel": "Microsoft-Windows-WebIO/Diagnostic",
"computer": "10.2.10.21",
"correlation": {},
"event_id": 126,
"event_record_id": 0,
"event_source_name": "",
"execution": {
"process_id": 4356,
"thread_id": 10668
},
"guid": "",
"keywords": 0,
"level": 4,
"opcode": 0,
"provider": "Microsoft-Windows-WebIO",
"security": {
"user_id": ""
},
"task": 0,
"time_created": "2026-07-22 01:49:47.518Z",
"version": 0
},
"event_data": {
"ChunkData": "0x25ABFE0215D",
"ChunkDataLength": 0,
"CompletionContext": "0x25AC1B04C30",
"CompletionInformation": 88,
"DataChunks": "0x25AC9612CF8",
"Error": 0,
"Request": "0x25AC1816540"
},
"message": ""
}
Event ID 127: Request: HTTP Receive (DataChunk DataChunks) (BytesToRecv BytesToReceive).
#Message #
Fields #
| Name | Description |
|---|---|
Request Pointer | |
DataChunks Pointer | |
BytesToReceive UInt32 | |
Error UInt32 | |
CompletionContext Pointer | |
CompletionInformation UInt64 |
Example Event #
{
"system": {
"channel": "Microsoft-Windows-WebIO/Diagnostic",
"computer": "10.2.10.21",
"correlation": {},
"event_id": 127,
"event_record_id": 0,
"event_source_name": "",
"execution": {
"process_id": 4236,
"thread_id": 12820
},
"guid": "",
"keywords": 0,
"level": 4,
"opcode": 1,
"provider": "Microsoft-Windows-WebIO",
"security": {
"user_id": ""
},
"task": 0,
"time_created": "2026-07-22 01:49:03.236Z",
"version": 0
},
"event_data": {
"BytesToReceive": 11,
"CompletionContext": "0x1CE140D42A0",
"CompletionInformation": 0,
"DataChunks": "0x1CE12383308",
"Error": 0,
"Request": "0x1CE0F728280"
},
"message": ""
}
Event ID 128: Request: HTTP Receive Complete (DataChunk DataChunks) (BytesToRecv BytesToReceive) (Error Error) (Context CompletionContext) (Information CompletionInformation).
#Message #
Fields #
| Name | Description |
|---|---|
Request Pointer | |
DataChunks Pointer | |
BytesToReceive UInt32 | |
Error UInt32 | |
CompletionContext Pointer | |
CompletionInformation UInt64 |
Example Event #
{
"system": {
"channel": "Microsoft-Windows-WebIO/Diagnostic",
"computer": "10.2.10.21",
"correlation": {},
"event_id": 128,
"event_record_id": 0,
"event_source_name": "",
"execution": {
"process_id": 4236,
"thread_id": 12820
},
"guid": "",
"keywords": 0,
"level": 4,
"opcode": 2,
"provider": "Microsoft-Windows-WebIO",
"security": {
"user_id": ""
},
"task": 0,
"time_created": "2026-07-22 01:49:03.236Z",
"version": 0
},
"event_data": {
"BytesToReceive": 11,
"CompletionContext": "0x1CE140D42A0",
"CompletionInformation": 11,
"DataChunks": "0x1CE12383308",
"Error": 0,
"Request": "0x1CE0F728280"
},
"message": ""
}
Event ID 129: Request: HTTP Receive Entity Details (DataChunk DataChunks) (Index Index) (Length Length) Data Data.
#Message #
Fields #
| Name | Description |
|---|---|
Request Pointer | |
DataChunks Pointer | |
Index UInt32 | |
Length UInt32 | |
Data Binary |
Example Event #
{
"system": {
"channel": "Microsoft-Windows-WebIO/Diagnostic",
"computer": "10.2.10.21",
"correlation": {},
"event_id": 129,
"event_record_id": 0,
"event_source_name": "",
"execution": {
"process_id": 4236,
"thread_id": 12820
},
"guid": "",
"keywords": 0,
"level": 4,
"opcode": 0,
"provider": "Microsoft-Windows-WebIO",
"security": {
"user_id": ""
},
"task": 0,
"time_created": "2026-07-22 01:49:03.236Z",
"version": 0
},
"event_data": {
"Data": "7B22616363223A3135377D",
"DataChunks": "0x1CE12383308",
"Index": 0,
"Length": 11,
"Request": "0x1CE0F728280"
},
"message": ""
}
Event ID 130: Request: WebSendHttpRequest (Handle: RequestHandle) (Flags: Flags) (DataChunks DataChunks [DataChunkCount]) CompletionContext (CompletionContext).
#Message #
Fields #
| Name | Description |
|---|---|
Request Pointer | |
RequestHandle UInt64 | |
Flags UInt32 | |
DataChunks Pointer | |
DataChunkCount UInt32 | |
CompletionContext Pointer | |
Error UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-WebIO",
"guid": "{50b3e73c-9370-461d-bb9f-26f32d68887d}",
"event_source_name": "",
"event_id": 130,
"version": 0,
"level": 4,
"task": 413,
"opcode": 1,
"keywords": "0x8000000100000001",
"time_created": "2026-07-19T03:58:54.638906300+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "30000002-0006-FC00-500F-468BBC32EC1F"
},
"execution": {
"process_id": 12988,
"thread_id": 8172
},
"channel": "Microsoft-Windows-WebIO/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Request": "0x1858B460F50",
"RequestHandle": "0xFC00000630000002",
"Flags": "0x0",
"DataChunks": "0x0",
"DataChunkCount": "0x0",
"CompletionContext": "0x1858D13B150",
"Error": "0x0"
},
"message": "0x1858B460F50: WebSendHttpRequest (Handle: 0xFC00000630000002) (Flags: 0x0) (DataChunks 0x0 [0x0]) CompletionContext (0x1858D13B150)"
}
Event ID 131: Request: WebSendHttpRequest Inline Completion (Handle: RequestHandle) (Error: Error) (Flags: Flags) (DataChunks DataChunks [DataChunkCount]) CompletionContext (CompletionContext).
#Message #
Fields #
| Name | Description |
|---|---|
Request Pointer | |
RequestHandle UInt64 | |
Flags UInt32 | |
DataChunks Pointer | |
DataChunkCount UInt32 | |
CompletionContext Pointer | |
Error UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-WebIO",
"guid": "{50b3e73c-9370-461d-bb9f-26f32d68887d}",
"event_source_name": "",
"event_id": 131,
"version": 0,
"level": 4,
"task": 413,
"opcode": 2,
"keywords": "0x8000000100000001",
"time_created": "2026-07-19T03:58:54.640265900+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "30000002-0006-FC00-500F-468BBC32EC1F"
},
"execution": {
"process_id": 12988,
"thread_id": 8172
},
"channel": "Microsoft-Windows-WebIO/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Request": "0x1858B460F50",
"RequestHandle": "0xFC00000630000002",
"Flags": "0x0",
"DataChunks": "0x0",
"DataChunkCount": "0x0",
"CompletionContext": "0x1858D13B150",
"Error": "0x3E5"
},
"message": "0x1858B460F50: WebSendHttpRequest Inline Completion (Handle: 0xFC00000630000002) (Error: Overlapped I/O operation is in progress.) (Flags: 0x0) (DataChunks 0x0 [0x0]) CompletionContext (0x1858D13B150)"
}
Event ID 132: Request: WebHttpReceiveResponse (Handle: RequestHandle) (Flags Flags) (ResponseFlags ResponseFlags) CompletionContext (CompletionContext).
#Message #
Fields #
| Name | Description |
|---|---|
Request Pointer | |
RequestHandle UInt64 | |
Flags UInt32 | |
ResponseFlags UInt32 | |
CompletionContext Pointer | |
Error UInt32 |
Example Event #
{
"system": {
"channel": "Microsoft-Windows-WebIO/Diagnostic",
"computer": "10.2.10.21",
"correlation": {},
"event_id": 132,
"event_record_id": 0,
"event_source_name": "",
"execution": {
"process_id": 9228,
"thread_id": 10624
},
"guid": "",
"keywords": 0,
"level": 4,
"opcode": 1,
"provider": "Microsoft-Windows-WebIO",
"security": {
"user_id": ""
},
"task": 0,
"time_created": "2026-07-22 01:49:20.416Z",
"version": 0
},
"event_data": {
"CompletionContext": "0x2D0FA284B30",
"Error": 0,
"Flags": 0,
"Request": "0x2D09186A540",
"RequestHandle": 18374686497656799233,
"ResponseFlags": 0
},
"message": ""
}
Event ID 133: Request: WebHttpReceiveEntityBody Inline Completion (Handle: RequestHandle) (Error: Error) (Flags: Flags) (ResponseFlags ResponseFlags) CompletionContext (CompletionContext).
#Message #
Fields #
| Name | Description |
|---|---|
Request Pointer | |
RequestHandle UInt64 | |
Flags UInt32 | |
ResponseFlags UInt32 | |
CompletionContext Pointer | |
Error UInt32 |
Example Event #
{
"system": {
"channel": "Microsoft-Windows-WebIO/Diagnostic",
"computer": "10.2.10.21",
"correlation": {},
"event_id": 133,
"event_record_id": 0,
"event_source_name": "",
"execution": {
"process_id": 9228,
"thread_id": 10624
},
"guid": "",
"keywords": 0,
"level": 4,
"opcode": 2,
"provider": "Microsoft-Windows-WebIO",
"security": {
"user_id": ""
},
"task": 0,
"time_created": "2026-07-22 01:49:20.416Z",
"version": 0
},
"event_data": {
"CompletionContext": "0x2D0FA284B30",
"Error": 0,
"Flags": 0,
"Request": "0x2D09186A540",
"RequestHandle": 18374686497656799233,
"ResponseFlags": 0
},
"message": ""
}
Event ID 134: Request: Completing WebHttpReceiveEntityBody (Error Error) (ResponseFlags ResponseFlags) (CompletionInformation CompletionContext).
#Message #
Fields #
| Name | Description |
|---|---|
Request Pointer | |
ResponseFlags UInt32 | |
Error UInt32 | |
CompletionContext Pointer |
Example Event #
{
"system": {
"channel": "Microsoft-Windows-WebIO/Diagnostic",
"computer": "10.2.10.21",
"correlation": {},
"event_id": 134,
"event_record_id": 0,
"event_source_name": "",
"execution": {
"process_id": 4236,
"thread_id": 12820
},
"guid": "",
"keywords": 0,
"level": 4,
"opcode": 1,
"provider": "Microsoft-Windows-WebIO",
"security": {
"user_id": ""
},
"task": 0,
"time_created": "2026-07-22 01:49:03.235Z",
"version": 0
},
"event_data": {
"CompletionContext": "0x1CE140D42A0",
"Error": 0,
"Request": "0x1CE0F728280",
"ResponseFlags": 0
},
"message": ""
}
Event ID 135: Request: Completing WebHttpReceiveEntityBody Complete.
#Message #
Fields #
| Name | Description |
|---|---|
Request Pointer | |
ResponseFlags UInt32 | |
Error UInt32 | |
CompletionContext Pointer |
Example Event #
{
"system": {
"channel": "Microsoft-Windows-WebIO/Diagnostic",
"computer": "10.2.10.21",
"correlation": {},
"event_id": 135,
"event_record_id": 0,
"event_source_name": "",
"execution": {
"process_id": 4236,
"thread_id": 12820
},
"guid": "",
"keywords": 0,
"level": 4,
"opcode": 2,
"provider": "Microsoft-Windows-WebIO",
"security": {
"user_id": ""
},
"task": 0,
"time_created": "2026-07-22 01:49:03.236Z",
"version": 0
},
"event_data": {
"CompletionContext": "0x1CE140D42A0",
"Error": 0,
"Request": "0x1CE0F728280",
"ResponseFlags": 0
},
"message": ""
}
Event ID 136: Request: WebCancelHttpRequest (Handle: RequestHandle) (Flags Flags).
#Message #
Fields #
| Name | Description |
|---|---|
Request Pointer | |
RequestHandle UInt64 | |
Flags UInt32 | |
Error UInt32 |
Example Event #
{
"system": {
"channel": "Microsoft-Windows-WebIO/Diagnostic",
"computer": "10.2.10.21",
"correlation": {},
"event_id": 136,
"event_record_id": 0,
"event_source_name": "",
"execution": {
"process_id": 1600,
"thread_id": 11792
},
"guid": "",
"keywords": 0,
"level": 4,
"opcode": 1,
"provider": "Microsoft-Windows-WebIO",
"security": {
"user_id": ""
},
"task": 0,
"time_created": "2026-07-22 01:49:30.631Z",
"version": 0
},
"event_data": {
"Error": 0,
"Flags": 0,
"Request": "0x1FDB4D85A40",
"RequestHandle": 18374686532016537601
},
"message": ""
}
Event ID 137: Request: WebCancelHttpRequest Complete (Error: Error) (Handle: RequestHandle) (Flags Flags).
#Message #
Fields #
| Name | Description |
|---|---|
Request Pointer | |
RequestHandle UInt64 | |
Flags UInt32 | |
Error UInt32 |
Example Event #
{
"system": {
"channel": "Microsoft-Windows-WebIO/Diagnostic",
"computer": "10.2.10.21",
"correlation": {},
"event_id": 137,
"event_record_id": 0,
"event_source_name": "",
"execution": {
"process_id": 1600,
"thread_id": 11792
},
"guid": "",
"keywords": 0,
"level": 4,
"opcode": 2,
"provider": "Microsoft-Windows-WebIO",
"security": {
"user_id": ""
},
"task": 0,
"time_created": "2026-07-22 01:49:30.631Z",
"version": 0
},
"event_data": {
"Error": 0,
"Flags": 0,
"Request": "0x1FDB4D85A40",
"RequestHandle": 18374686532016537601
},
"message": ""
}
Event ID 200: Connection: Connecting (Socket SocketHandle) (Context Context) (RemaingAddress RemainingAddressCount) Address: Address.
#Message #
Fields #
| Name | Description |
|---|---|
Connection Pointer | |
SocketHandle UInt64 | |
AddressLength UInt32 | |
Address UnicodeString | |
Context Pointer | |
RemainingAddressCount UInt64 | |
Error UInt32 | |
Http3ClientConnectionId UInt64 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-WebIO",
"guid": "{50b3e73c-9370-461d-bb9f-26f32d68887d}",
"event_source_name": "",
"event_id": 200,
"version": 1,
"level": 4,
"task": 417,
"opcode": 1,
"keywords": "0x8000000400000000",
"time_created": "2026-07-19T03:58:54.639838800+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "30000002-0006-FC00-500F-468BBC32EC1F"
},
"execution": {
"process_id": 12988,
"thread_id": 8172
},
"channel": "Microsoft-Windows-WebIO/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Connection": "0x1858D0863A0",
"SocketHandle": "0x8CC",
"AddressLength": "16",
"Address": "127.0.0.1:18093",
"Context": "0x1858D148650",
"RemainingAddressCount": "0x6",
"Error": "0x0",
"Http3ClientConnectionId": "0x0"
},
"message": "0x1858D0863A0: Connecting (Socket 0x8CC) (Context 0x1858D148650) (RemaingAddress 0x6) Address: 127.0.0.1:18093. (H/3 Connection 0x0)"
}
Event ID 201: Connection: Connection established (Socket SocketHandle) (Context Context).
#Message #
Fields #
| Name | Description |
|---|---|
Connection Pointer | |
SocketHandle UInt64 | |
AddressLength UInt32 | |
Address UnicodeString | |
Context Pointer | |
RemainingAddressCount UInt64 | |
Error UInt32 | |
Http3ClientConnectionId UInt64 |
Example Event #
{
"system": {
"channel": "Microsoft-Windows-WebIO/Diagnostic",
"computer": "10.2.10.21",
"correlation": {},
"event_id": 201,
"event_record_id": 0,
"event_source_name": "",
"execution": {
"process_id": 9228,
"thread_id": 13156
},
"guid": "",
"keywords": 0,
"level": 4,
"opcode": 2,
"provider": "Microsoft-Windows-WebIO",
"security": {
"user_id": ""
},
"task": 0,
"time_created": "2026-07-22 01:49:19.988Z",
"version": 0
},
"event_data": {
"Address": "",
"AddressLength": 0,
"Connection": "0x2D0FA7C6940",
"Context": "0x2D0FA281AD0",
"Error": 0,
"Http3ClientConnectionId": 0,
"RemainingAddressCount": 6,
"SocketHandle": 2980
},
"message": ""
}
Event ID 202: Connection: Connect failed with error Error (Socket SocketHandle) (Context Context) (RemaingAddress RemainingAddressCount).
#Message #
Fields #
| Name | Description |
|---|---|
Connection Pointer | |
SocketHandle UInt64 | |
AddressLength UInt32 | |
Address UnicodeString | |
Context Pointer | |
RemainingAddressCount UInt64 | |
Error UInt32 | |
Http3ClientConnectionId UInt64 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-WebIO",
"guid": "{50b3e73c-9370-461d-bb9f-26f32d68887d}",
"event_source_name": "",
"event_id": 202,
"version": 1,
"level": 2,
"task": 417,
"opcode": 2,
"keywords": "0x8000000400000000",
"time_created": "2026-07-19T03:58:56.684669200+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "30000002-0006-FC00-500F-468BBC32EC1F"
},
"execution": {
"process_id": 12988,
"thread_id": 5876
},
"channel": "Microsoft-Windows-WebIO/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Connection": "0x1858D0863A0",
"SocketHandle": "0x8CC",
"AddressLength": "0",
"Address": "",
"Context": "0x1858D148650",
"RemainingAddressCount": "0x5",
"Error": "0x274D",
"Http3ClientConnectionId": "0x0"
},
"message": "0x1858D0863A0: Connect failed with error No connection could be made because the target machine actively refused it. (Socket 0x8CC) (Context 0x1858D148650) (RemaingAddress 0x5). (H/3 Connection 0x0)"
}
Event ID 203: Socket SocketHandle created on Endpoint Connection.
#Message #
Fields #
| Name | Description |
|---|---|
Connection Pointer | |
SocketHandle UInt64 | |
Error UInt32 | |
Http3ClientConnectionId UInt64 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-WebIO",
"guid": "{50b3e73c-9370-461d-bb9f-26f32d68887d}",
"event_source_name": "",
"event_id": 203,
"version": 1,
"level": 4,
"task": 418,
"opcode": 0,
"keywords": "0x8000000000000000",
"time_created": "2026-07-19T03:58:54.639479500+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "30000002-0006-FC00-500F-468BBC32EC1F"
},
"execution": {
"process_id": 12988,
"thread_id": 8172
},
"channel": "Microsoft-Windows-WebIO/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Connection": "0x1858D0863A0",
"SocketHandle": "0x8CC",
"Error": "0x0",
"Http3ClientConnectionId": "0x0"
},
"message": "Socket 0x8CC created on Endpoint 0x1858D0863A0. H/3 Connection 0x0"
}
Event ID 204: Endpoint: Socket Socket Closed (Reason = Reason, Status = Result).
#Message #
Fields #
| Name | Description |
|---|---|
Endpoint Pointer | |
Socket UInt64 | |
Reason UInt32 | |
Result UInt32 | |
Http3ClientConnectionId UInt64 | |
Aborted Boolean |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-WebIO",
"guid": "{50B3E73C-9370-461D-BB9F-26F32D68887D}",
"event_source_name": "",
"event_id": 204,
"version": 0,
"level": 4,
"task": 419,
"opcode": 0,
"keywords": "0x0000000000000000",
"time_created": "2026-06-02T04:01:52.944+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{EB64A0B3-7FFC-0000-D588-CD01FC2D780D}"
},
"execution": {
"process_id": 11772,
"thread_id": 13132
},
"channel": "ETW Trace",
"computer": "JD-DC01-2022",
"security": {
"user_id": ""
}
},
"event_data": {
"Endpoint": "0x23E900EFC70",
"Reason": 8,
"Result": 0,
"Socket": 1756
},
"message": "Task.ConnectionSocketClose"
}
Event ID 205: DnsQuery: Name Resolution Request (Name HostName) (Timeout Timeout) (CompletionContext: CompletionContext).
#Message #
Fields #
| Name | Description |
|---|---|
DnsQuery Pointer | |
HostName UnicodeString | |
Timeout UInt32 | |
CompletionContext UInt64 |
Example Event #
{
"system": {
"channel": "Microsoft-Windows-WebIO/Diagnostic",
"computer": "10.2.10.21",
"correlation": {},
"event_id": 205,
"event_record_id": 0,
"event_source_name": "",
"execution": {
"process_id": 9228,
"thread_id": 8044
},
"guid": "",
"keywords": 0,
"level": 4,
"opcode": 1,
"provider": "Microsoft-Windows-WebIO",
"security": {
"user_id": ""
},
"task": 0,
"time_created": "2026-07-22 01:49:19.856Z",
"version": 0
},
"event_data": {
"CompletionContext": 3096573384640,
"DnsQuery": "0x2D0FA7C6940",
"HostName": "fe2cr.update.microsoft.com/v6/ClientWebService/client.asmx",
"Timeout": 0
},
"message": ""
}
Event ID 206: DnsQuery: Name Resolution Request Completed (FQDN FQDN) (Canonical CanonicalName) (AddressCount: AddressCount) AddressData: SockAddr.
#Message #
Fields #
| Name | Description |
|---|---|
DnsQuery Pointer | |
FQDN UnicodeString | |
CanonicalName UnicodeString | |
AddressCount UInt32 | |
SockaddrLength UInt32 | |
SockAddr Binary |
Example Event #
{
"system": {
"channel": "Microsoft-Windows-WebIO/Diagnostic",
"computer": "10.2.10.21",
"correlation": {},
"event_id": 206,
"event_record_id": 0,
"event_source_name": "",
"execution": {
"process_id": 9228,
"thread_id": 13156
},
"guid": "",
"keywords": 0,
"level": 4,
"opcode": 2,
"provider": "Microsoft-Windows-WebIO",
"security": {
"user_id": ""
},
"task": 0,
"time_created": "2026-07-22 01:49:19.886Z",
"version": 0
},
"event_data": {
"AddressCount": 2,
"CanonicalName": "fe2cr.update.msft.com.trafficmanager.net",
"DnsQuery": "0x2D0FA7C6940",
"FQDN": "fe2cr.update.microsoft.com",
"SockAddr": "020000008621B96200000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000871280D3000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000",
"SockaddrLength": 256
},
"message": ""
}
Event ID 207: DnsQuery: Name Resolution Request Failed (Error Error).
#Event ID 208: DnsQuery: Name Resolution Request queued to CacheEntry.
#Message #
Fields #
| Name | Description |
|---|---|
DnsQuery Pointer | |
CacheEntry Pointer |
Example Event #
{
"system": {
"channel": "Microsoft-Windows-WebIO/Diagnostic",
"computer": "10.2.10.21",
"correlation": {},
"event_id": 208,
"event_record_id": 0,
"event_source_name": "",
"execution": {
"process_id": 9228,
"thread_id": 8044
},
"guid": "",
"keywords": 0,
"level": 4,
"opcode": 0,
"provider": "Microsoft-Windows-WebIO",
"security": {
"user_id": ""
},
"task": 0,
"time_created": "2026-07-22 01:49:19.856Z",
"version": 0
},
"event_data": {
"CacheEntry": "0x2D0FA6FC0D0",
"DnsQuery": "0x2D0FA7C6940"
},
"message": ""
}
Event ID 209: ReferenceContext: Name Resolution Request is cancelled.
#Event ID 210: ReferenceContext: Name Resolution Request Timed-out.
#Event ID 211: CacheEntry: Resolving addresses (Host ResolveName) (Flags: Flags).
#Message #
Fields #
| Name | Description |
|---|---|
CacheEntry Pointer | |
ResolveName UnicodeString | |
Flags UInt32 | |
Error UInt32 | |
AddressCount UInt32 |
Example Event #
{
"system": {
"channel": "Microsoft-Windows-WebIO/Diagnostic",
"computer": "10.2.10.21",
"correlation": {},
"event_id": 211,
"event_record_id": 0,
"event_source_name": "",
"execution": {
"process_id": 9228,
"thread_id": 8044
},
"guid": "",
"keywords": 0,
"level": 4,
"opcode": 1,
"provider": "Microsoft-Windows-WebIO",
"security": {
"user_id": ""
},
"task": 0,
"time_created": "2026-07-22 01:49:19.856Z",
"version": 0
},
"event_data": {
"AddressCount": 0,
"CacheEntry": "0x2D0FA215DD0",
"Error": 0,
"Flags": 131074,
"ResolveName": "fe2cr.update.microsoft.com"
},
"message": ""
}
Event ID 212: CacheEntry: Address resolution completed (Error = Error) (Host ResolveName) (Flags: Flags).
#Description
CacheEntry: Address resolution completed (Error = Error) (Host ResolveName) (Flags: Flags).(AddressCount AddressCount).
Message #
Fields #
| Name | Description |
|---|---|
CacheEntry Pointer | |
ResolveName UnicodeString | |
Flags UInt32 | |
Error UInt32 | |
AddressCount UInt32 |
Example Event #
{
"system": {
"channel": "Microsoft-Windows-WebIO/Diagnostic",
"computer": "10.2.10.21",
"correlation": {},
"event_id": 212,
"event_record_id": 0,
"event_source_name": "",
"execution": {
"process_id": 9228,
"thread_id": 13156
},
"guid": "",
"keywords": 0,
"level": 4,
"opcode": 2,
"provider": "Microsoft-Windows-WebIO",
"security": {
"user_id": ""
},
"task": 0,
"time_created": "2026-07-22 01:49:19.886Z",
"version": 0
},
"event_data": {
"AddressCount": 2,
"CacheEntry": "0x2D0FA215DD0",
"Error": 0,
"Flags": 0,
"ResolveName": "fe2cr.update.microsoft.com"
},
"message": ""
}
Event ID 213: Connection: Winsock Send Entity Start(DataChunks DataChunks) (Socket SocketHandle) (Buffers Buffer) (Context Context).
#Message #
Fields #
| Name | Description |
|---|---|
Connection Pointer | |
DataChunks Pointer | |
SocketHandle UInt64 | |
Buffer Pointer | |
Context Pointer | |
Error UInt32 | |
Information UInt64 | |
Http3ClientStreamId UInt64 | |
BufferLength UInt64 | |
IsEof Boolean | |
IsHeaderPairs Boolean |
Example Event #
{
"system": {
"channel": "Microsoft-Windows-WebIO/Diagnostic",
"computer": "10.2.10.21",
"correlation": {},
"event_id": 213,
"event_record_id": 0,
"event_source_name": "",
"execution": {
"process_id": 9228,
"thread_id": 13156
},
"guid": "",
"keywords": 0,
"level": 4,
"opcode": 1,
"provider": "Microsoft-Windows-WebIO",
"security": {
"user_id": ""
},
"task": 0,
"time_created": "2026-07-22 01:49:19.990Z",
"version": 0
},
"event_data": {
"Buffer": "0x2D0FA221C30",
"BufferLength": 0,
"Connection": "0x2D0FA7C6940",
"Context": "0x2D0FA221AE0",
"DataChunks": "0x2D0FA271CF0",
"Error": 0,
"Http3ClientStreamId": 0,
"Information": 0,
"IsEof": false,
"IsHeaderPairs": true,
"SocketHandle": 2980
},
"message": ""
}
Event ID 214: Connection: Winsock Send Entity Complete (Error Error) (Information Information) (Socket SocketHandle) (Buffers Buffer) (Context Context).
#Message #
Fields #
| Name | Description |
|---|---|
Connection Pointer | |
DataChunks Pointer | |
SocketHandle UInt64 | |
Buffer Pointer | |
Context Pointer | |
Error UInt32 | |
Information UInt64 | |
Http3ClientStreamId UInt64 | |
BufferLength UInt64 | |
IsEof Boolean | |
IsHeaderPairs Boolean |
Example Event #
{
"system": {
"channel": "Microsoft-Windows-WebIO/Diagnostic",
"computer": "10.2.10.21",
"correlation": {},
"event_id": 214,
"event_record_id": 0,
"event_source_name": "",
"execution": {
"process_id": 9228,
"thread_id": 13156
},
"guid": "",
"keywords": 0,
"level": 4,
"opcode": 2,
"provider": "Microsoft-Windows-WebIO",
"security": {
"user_id": ""
},
"task": 0,
"time_created": "2026-07-22 01:49:19.990Z",
"version": 0
},
"event_data": {
"Buffer": "0x2D0FA221C30",
"BufferLength": 0,
"Connection": "0x2D0FA7C6940",
"Context": "0x2D0FA221AE0",
"DataChunks": "0x0",
"Error": 0,
"Http3ClientStreamId": 0,
"Information": 209,
"IsEof": false,
"IsHeaderPairs": true,
"SocketHandle": 2980
},
"message": ""
}
Event ID 215: Connection: Winsock Recv Entity Start (DataChunks DataChunks) (Socket SocketHandle) (Buffers Buffer) (Context Context).
#Message #
Fields #
| Name | Description |
|---|---|
Connection Pointer | |
DataChunks Pointer | |
SocketHandle UInt64 | |
Buffer Pointer | |
Context Pointer | |
Error UInt32 | |
Information UInt64 | |
Http3ClientStreamId UInt64 | |
BufferLength UInt64 | |
IsEof Boolean | |
IsHeaderPairs Boolean |
Example Event #
{
"system": {
"channel": "Microsoft-Windows-WebIO/Diagnostic",
"computer": "10.2.10.21",
"correlation": {},
"event_id": 215,
"event_record_id": 0,
"event_source_name": "",
"execution": {
"process_id": 4236,
"thread_id": 9976
},
"guid": "",
"keywords": 0,
"level": 4,
"opcode": 1,
"provider": "Microsoft-Windows-WebIO",
"security": {
"user_id": ""
},
"task": 0,
"time_created": "2026-07-22 01:49:00.190Z",
"version": 0
},
"event_data": {
"Buffer": "0x1CE13B32BC0",
"BufferLength": 0,
"Connection": "0x1CE1368D240",
"Context": "0x1CE13B32A70",
"DataChunks": "0x1CE1368DCC8",
"Error": 0,
"Http3ClientStreamId": 0,
"Information": 0,
"IsEof": false,
"IsHeaderPairs": true,
"SocketHandle": 4908
},
"message": ""
}
Event ID 216: Connection: Winsock Recv Entity Complete(Error Error) (Information Information) (Socket SocketHandle) (Buffers Buffer) (Context Context).
#Message #
Fields #
| Name | Description |
|---|---|
Connection Pointer | |
DataChunks Pointer | |
SocketHandle UInt64 | |
Buffer Pointer | |
Context Pointer | |
Error UInt32 | |
Information UInt64 | |
Http3ClientStreamId UInt64 | |
BufferLength UInt64 | |
IsEof Boolean | |
IsHeaderPairs Boolean |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-WebIO",
"guid": "{50B3E73C-9370-461D-BB9F-26F32D68887D}",
"event_source_name": "",
"event_id": 216,
"version": 0,
"level": 4,
"task": 423,
"opcode": 2,
"keywords": "0x0000000200000000",
"time_created": "2026-06-02T04:01:52.944+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{30000002-0007-FE00-80D9-0A91FC2DA028}"
},
"execution": {
"process_id": 11772,
"thread_id": 3448
},
"channel": "ETW Trace",
"computer": "JD-DC01-2022",
"security": {
"user_id": ""
}
},
"event_data": {
"Buffer": "0x23E9009FB00",
"Connection": "0x23E900EFC70",
"Context": "0x23E9009F9B0",
"DataChunks": "0x0",
"Error": 995,
"Information": 0,
"SocketHandle": 18446744073709551615
},
"message": "Task.ConnectionSocketReceive"
}
Event ID 217: Connection: (H/3 Connection ID Http3ClientConnectionId) Got Stream (Stream Connection StreamConnection) (H/3 Stream ID Http3ClientStreamId).
#Event ID 218: Connection: Read Stream Data Indicated (StreamId StreamId) (Size Size) (Headers Headers).
#Message #
Fields #
| Name | Description |
|---|---|
Connection Pointer | |
StreamId UInt32 | |
Size UInt32 | |
Headers Boolean |
Example Event #
{
"system": {
"channel": "Microsoft-Windows-WebIO/Diagnostic",
"computer": "10.2.10.21",
"correlation": {},
"event_id": 218,
"event_record_id": 0,
"event_source_name": "",
"execution": {
"process_id": 4236,
"thread_id": 9976
},
"guid": "",
"keywords": 0,
"level": 4,
"opcode": 0,
"provider": "Microsoft-Windows-WebIO",
"security": {
"user_id": ""
},
"task": 0,
"time_created": "2026-07-22 01:49:03.235Z",
"version": 0
},
"event_data": {
"Connection": "0x1CE11907080",
"Headers": true,
"Size": 363,
"StreamId": 1
},
"message": ""
}
Event ID 219: Connection: Stream Created (StreamId StreamId).
#Message #
Fields #
| Name | Description |
|---|---|
Connection Pointer | |
StreamId UInt32 |
Example Event #
{
"system": {
"channel": "Microsoft-Windows-WebIO/Diagnostic",
"computer": "10.2.10.21",
"correlation": {},
"event_id": 219,
"event_record_id": 0,
"event_source_name": "",
"execution": {
"process_id": 9228,
"thread_id": 13156
},
"guid": "",
"keywords": 0,
"level": 4,
"opcode": 0,
"provider": "Microsoft-Windows-WebIO",
"security": {
"user_id": ""
},
"task": 0,
"time_created": "2026-07-22 01:49:20.177Z",
"version": 0
},
"event_data": {
"Connection": "0x2D090AFE040",
"StreamId": 1
},
"message": ""
}
Event ID 220: Connection: Stream Aborted (StreamId StreamId) (HRESULT error Error) (Reset Code ResetCode).
#Message #
Fields #
| Name | Description |
|---|---|
Connection Pointer | |
StreamId UInt32 | |
Error Int32 | |
ResetCode UInt32 |
Example Event #
{
"system": {
"channel": "Microsoft-Windows-WebIO/Diagnostic",
"computer": "10.2.10.21",
"correlation": {},
"event_id": 220,
"event_record_id": 0,
"event_source_name": "",
"execution": {
"process_id": 4236,
"thread_id": 12820
},
"guid": "",
"keywords": 0,
"level": 4,
"opcode": 0,
"provider": "Microsoft-Windows-WebIO",
"security": {
"user_id": ""
},
"task": 0,
"time_created": "2026-07-22 01:49:03.236Z",
"version": 0
},
"event_data": {
"Connection": "0x1CE11907080",
"Error": -2147023901,
"ResetCode": 0,
"StreamId": 1
},
"message": ""
}
Event ID 221: Connection: Processing Initial HTTP/2 Setting (Id SettingId) (Value SettingValue).
#Message #
Fields #
| Name | Description |
|---|---|
Connection Pointer | |
SettingId UInt16 | |
SettingValue UInt32 |
Example Event #
{
"system": {
"channel": "Microsoft-Windows-WebIO/Diagnostic",
"computer": "10.2.10.21",
"correlation": {},
"event_id": 221,
"event_record_id": 0,
"event_source_name": "",
"execution": {
"process_id": 9228,
"thread_id": 13156
},
"guid": "",
"keywords": 0,
"level": 4,
"opcode": 0,
"provider": "Microsoft-Windows-WebIO",
"security": {
"user_id": ""
},
"task": 0,
"time_created": "2026-07-22 01:49:20.178Z",
"version": 0
},
"event_data": {
"Connection": "0x2D0FA7C6940",
"SettingId": 3,
"SettingValue": 100
},
"message": ""
}
Event ID 222: Connection: Received WINDOW_UPDATE frame (StreamId StreamId) (WindowIncrement WindowIncrement) (IsSession IsSession).
#Message #
Fields #
| Name | Description |
|---|---|
Connection Pointer | |
StreamId UInt32 | |
WindowIncrement UInt32 | |
IsSession Boolean |
Example Event #
{
"system": {
"channel": "Microsoft-Windows-WebIO/Diagnostic",
"computer": "10.2.10.21",
"correlation": {},
"event_id": 222,
"event_record_id": 0,
"event_source_name": "",
"execution": {
"process_id": 4236,
"thread_id": 9976
},
"guid": "",
"keywords": 0,
"level": 4,
"opcode": 0,
"provider": "Microsoft-Windows-WebIO",
"security": {
"user_id": ""
},
"task": 0,
"time_created": "2026-07-22 01:49:00.190Z",
"version": 0
},
"event_data": {
"Connection": "0x1CE1368D240",
"IsSession": true,
"StreamId": 0,
"WindowIncrement": 73728
},
"message": ""
}
Event ID 223: Connection: Received GOAWAY frame (LastStreamId LastStreamId) (Error Error).
#Event ID 224: Connection: HTTP/2 Connection Aborted (Error Error).
#Message #
Fields #
| Name | Description |
|---|---|
Connection Pointer | |
Error Int32 |
Example Event #
{
"system": {
"channel": "Microsoft-Windows-WebIO/Diagnostic",
"computer": "10.2.10.21",
"correlation": {},
"event_id": 224,
"event_record_id": 0,
"event_source_name": "",
"execution": {
"process_id": 4236,
"thread_id": 8496
},
"guid": "",
"keywords": 0,
"level": 4,
"opcode": 0,
"provider": "Microsoft-Windows-WebIO",
"security": {
"user_id": ""
},
"task": 0,
"time_created": "2026-07-22 01:49:03.242Z",
"version": 0
},
"event_data": {
"Connection": "0x1CE1368D240",
"Error": -2147023901
},
"message": ""
}
Event ID 225: Connection: HTTP/2 send window reached flow-control limit (StreamId StreamId) (IsSession IsSession).
#Event ID 700: Connection: InitializeSecurityContext - Credential Handle(SecurityHandleHigh:SecurityHandleLow) Context Handle (CredHandleHigh:CredHandleLow) (Hostname HostName) (InputFlags InputFlags) (Buffer Buf...
#Description
Connection: InitializeSecurityContext - Credential Handle(SecurityHandleHigh:SecurityHandleLow) Context Handle (CredHandleHigh:CredHandleLow) (Hostname HostName) (InputFlags InputFlags) (Buffer Buffer [BufferLengthData/BufferLengthRemaining]).
Message #
Fields #
| Name | Description |
|---|---|
Connection Pointer | |
SecurityHandleHigh UInt64 | |
SecurityHandleLow UInt64 | |
CredHandleHigh UInt64 | |
CredHandleLow UInt64 | |
HostName UnicodeString | |
InputFlags UInt32 | |
Buffer Pointer | |
BufferLengthData UInt32 | |
BufferLengthRemaining UInt32 | |
OutputFlags UInt32 | |
DataChunks Pointer | |
DataChunkBufferLength UInt32 | |
Result UInt32 |
Example Event #
{
"system": {
"channel": "Microsoft-Windows-WebIO/Diagnostic",
"computer": "10.2.10.21",
"correlation": {},
"event_id": 700,
"event_record_id": 0,
"event_source_name": "",
"execution": {
"process_id": 9228,
"thread_id": 13156
},
"guid": "",
"keywords": 0,
"level": 4,
"opcode": 1,
"provider": "Microsoft-Windows-WebIO",
"security": {
"user_id": ""
},
"task": 0,
"time_created": "2026-07-22 01:49:19.989Z",
"version": 0
},
"event_data": {
"Buffer": "0x0",
"BufferLengthData": 0,
"BufferLengthRemaining": 0,
"Connection": "0x2D0FA7C6940",
"CredHandleHigh": 80330,
"CredHandleLow": 3096573701856,
"DataChunkBufferLength": 0,
"DataChunks": "0x0",
"HostName": "fe2cr.update.microsoft.com",
"InputFlags": 49564,
"OutputFlags": 0,
"Result": 0,
"SecurityHandleHigh": 18446744073709551615,
"SecurityHandleLow": 18446744073709551615
},
"message": ""
}
Event ID 703: Connection: InitializeSecurityContext returned - (Result) Credential Handle(SecurityHandleHigh:SecurityHandleLow) Context Handle (CredHandleHigh:CredHandleLow) (OutputFlags OutputFlags) (Buffer Buf...
#Description
Connection: InitializeSecurityContext returned - (Result) Credential Handle(SecurityHandleHigh:SecurityHandleLow) Context Handle (CredHandleHigh:CredHandleLow) (OutputFlags OutputFlags) (Buffer Buffer [BufferLengthData/BufferLengthRemaining]) (DataChunk DataChunks [DataChunkBufferLength]).
Message #
Fields #
| Name | Description |
|---|---|
Connection Pointer | |
SecurityHandleHigh UInt64 | |
SecurityHandleLow UInt64 | |
CredHandleHigh UInt64 | |
CredHandleLow UInt64 | |
HostName UnicodeString | |
InputFlags UInt32 | |
Buffer Pointer | |
BufferLengthData UInt32 | |
BufferLengthRemaining UInt32 | |
OutputFlags UInt32 | |
DataChunks Pointer | |
DataChunkBufferLength UInt32 | |
Result UInt32 |
Example Event #
{
"system": {
"channel": "Microsoft-Windows-WebIO/Diagnostic",
"computer": "10.2.10.21",
"correlation": {},
"event_id": 703,
"event_record_id": 0,
"event_source_name": "",
"execution": {
"process_id": 9228,
"thread_id": 13156
},
"guid": "",
"keywords": 0,
"level": 4,
"opcode": 2,
"provider": "Microsoft-Windows-WebIO",
"security": {
"user_id": ""
},
"task": 0,
"time_created": "2026-07-22 01:49:19.990Z",
"version": 0
},
"event_data": {
"Buffer": "0x0",
"BufferLengthData": 0,
"BufferLengthRemaining": 0,
"Connection": "0x2D0FA7C6940",
"CredHandleHigh": 80330,
"CredHandleLow": 3096573701856,
"DataChunkBufferLength": 209,
"DataChunks": "0x2D0FA271CF0",
"HostName": "fe2cr.update.microsoft.com",
"InputFlags": 49564,
"OutputFlags": 49564,
"Result": 590610,
"SecurityHandleHigh": 80331,
"SecurityHandleLow": 3096573701856
},
"message": ""
}
Event ID 704: Connection: InitializeSecurityContext Details (Pre) - Credential Handle(SecurityHandleHigh:SecurityHandleLow) (Buffer Buffer [BufferLengthData/BufferLengthRemaining]) Data: Data.
#Message #
Fields #
| Name | Description |
|---|---|
Connection Pointer | |
SecurityHandleHigh UInt64 | |
SecurityHandleLow UInt64 | |
Buffer Pointer | |
BufferLengthData UInt32 | |
BufferLengthRemaining UInt32 | |
Data Binary |
Example Event #
{
"system": {
"channel": "Microsoft-Windows-WebIO/Diagnostic",
"computer": "10.2.10.21",
"correlation": {},
"event_id": 704,
"event_record_id": 0,
"event_source_name": "",
"execution": {
"process_id": 9228,
"thread_id": 13156
},
"guid": "",
"keywords": 0,
"level": 4,
"opcode": 0,
"provider": "Microsoft-Windows-WebIO",
"security": {
"user_id": ""
},
"task": 0,
"time_created": "2026-07-22 01:49:19.989Z",
"version": 0
},
"event_data": {
"Buffer": "0x0",
"BufferLengthData": 0,
"BufferLengthRemaining": 0,
"Connection": "0x2D0FA7C6940",
"Data": "",
"SecurityHandleHigh": 18446744073709551615,
"SecurityHandleLow": 18446744073709551615
},
"message": ""
}
Event ID 705: Connection: InitializeSecurityContext Details (Post) - Credential Handle(SecurityHandleHigh:SecurityHandleLow) (DataChunk DataChunks [DataChunkBufferLength]) Data: Data.
#Message #
Fields #
| Name | Description |
|---|---|
Connection Pointer | |
SecurityHandleHigh UInt64 | |
SecurityHandleLow UInt64 | |
DataChunks Pointer | |
DataChunkBufferLength UInt32 | |
Data Binary |
Example Event #
{
"system": {
"channel": "Microsoft-Windows-WebIO/Diagnostic",
"computer": "10.2.10.21",
"correlation": {},
"event_id": 705,
"event_record_id": 0,
"event_source_name": "",
"execution": {
"process_id": 9228,
"thread_id": 13156
},
"guid": "",
"keywords": 0,
"level": 4,
"opcode": 0,
"provider": "Microsoft-Windows-WebIO",
"security": {
"user_id": ""
},
"task": 0,
"time_created": "2026-07-22 01:49:19.990Z",
"version": 0
},
"event_data": {
"Connection": "0x2D0FA7C6940",
"Data": "16030300CC010000C803036A60219FC81B70953E7F6DB0CC50DA7F688191AF3242888C8042ED4A865E023D000024C02CC02BC030C02FC024C023C028C027C00AC009C014C013009D009C003D003C0035002F0100007B0000001F001D00001A66653263722E7570646174652E6D6963726F736F66742E636F6D000500050100000000000A00080006001D00170018000B00020100000D001A0018080408050806040105010201040305030203020206010603002300000010000E000C02683208687474702F312E3100170000FF01000100",
"DataChunkBufferLength": 209,
"DataChunks": "0x2D0FA271CF0",
"SecurityHandleHigh": 80331,
"SecurityHandleLow": 3096573701856
},
"message": ""
}
Event ID 706: Connection: SSL Encryption (SSLIOContext SslIOContext) Context Handle(CredHandleHigh:CredHandleLow) (DataChunks: DataChunks) (Index: Index) (OutBuffer: Buffer[Length]) (Flags Flags).
#Message #
Fields #
| Name | Description |
|---|---|
Connection Pointer | |
SslIOContext Pointer | |
CredHandleHigh UInt64 | |
CredHandleLow UInt64 | |
DataChunks Pointer | |
Index UInt32 | |
Buffer Pointer | |
Length UInt64 | |
Flags UInt32 | |
Error UInt32 |
Example Event #
{
"system": {
"channel": "Microsoft-Windows-WebIO/Diagnostic",
"computer": "10.2.10.21",
"correlation": {},
"event_id": 706,
"event_record_id": 0,
"event_source_name": "",
"execution": {
"process_id": 9228,
"thread_id": 13156
},
"guid": "",
"keywords": 0,
"level": 4,
"opcode": 1,
"provider": "Microsoft-Windows-WebIO",
"security": {
"user_id": ""
},
"task": 0,
"time_created": "2026-07-22 01:49:20.176Z",
"version": 0
},
"event_data": {
"Buffer": "0x2D0FA61C370",
"Connection": "0x2D0FA7C6940",
"CredHandleHigh": 80331,
"CredHandleLow": 3096573701856,
"DataChunks": "0x2D090A98CD0",
"Error": 0,
"Flags": 0,
"Index": 0,
"Length": 87,
"SslIOContext": "0x2D0FA271730"
},
"message": ""
}
Event ID 707: Connection: SSL Encryption Complete (SSLIOContext SslIOContext) (ErrorCode: Error) Context Handle(CredHandleHigh:CredHandleLow) (DataChunks: DataChunks) (Index: Index) (InBuffer: Buffer[Length]) (F...
#Description
Connection: SSL Encryption Complete (SSLIOContext SslIOContext) (ErrorCode: Error) Context Handle(CredHandleHigh:CredHandleLow) (DataChunks: DataChunks) (Index: Index) (InBuffer: Buffer[Length]) (Flags Flags).
Message #
Fields #
| Name | Description |
|---|---|
Connection Pointer | |
SslIOContext Pointer | |
CredHandleHigh UInt64 | |
CredHandleLow UInt64 | |
DataChunks Pointer | |
Index UInt32 | |
Buffer Pointer | |
Length UInt64 | |
Flags UInt32 | |
Error UInt32 |
Example Event #
{
"system": {
"channel": "Microsoft-Windows-WebIO/Diagnostic",
"computer": "10.2.10.21",
"correlation": {},
"event_id": 707,
"event_record_id": 0,
"event_source_name": "",
"execution": {
"process_id": 9228,
"thread_id": 13156
},
"guid": "",
"keywords": 0,
"level": 4,
"opcode": 2,
"provider": "Microsoft-Windows-WebIO",
"security": {
"user_id": ""
},
"task": 0,
"time_created": "2026-07-22 01:49:20.176Z",
"version": 0
},
"event_data": {
"Buffer": "0x2D0FA61C370",
"Connection": "0x2D0FA7C6940",
"CredHandleHigh": 80331,
"CredHandleLow": 3096573701856,
"DataChunks": "0x2D090A98CD0",
"Error": 0,
"Flags": 0,
"Index": 0,
"Length": 87,
"SslIOContext": "0x2D0FA271730"
},
"message": ""
}
Event ID 708: Connection: SSL Encryption Failed (SSLIOContext SslIOContext) (ErrorCode: Error) Context Handle(CredHandleHigh:CredHandleLow) (DataChunks: DataChunks) (Index: Index) (Flags Flags).
#Event ID 709: Connection: SSL Encryption Details (SSLIOContext SslIOContext) Context Handle(CredHandleHigh:CredHandleLow) (DataChunks: DataChunks) (Index: Index) (OutBuffer: Buffer[Length]) (Flags Flags) Data:Data.
#Message #
Fields #
| Name | Description |
|---|---|
Connection Pointer | |
SslIOContext Pointer | |
CredHandleHigh UInt64 | |
CredHandleLow UInt64 | |
DataChunks Pointer | |
Index UInt32 | |
Buffer Pointer | |
Length UInt32 | |
Flags UInt32 | |
Data Binary |
Example Event #
{
"system": {
"channel": "Microsoft-Windows-WebIO/Diagnostic",
"computer": "10.2.10.21",
"correlation": {},
"event_id": 709,
"event_record_id": 0,
"event_source_name": "",
"execution": {
"process_id": 9228,
"thread_id": 13156
},
"guid": "",
"keywords": 0,
"level": 4,
"opcode": 0,
"provider": "Microsoft-Windows-WebIO",
"security": {
"user_id": ""
},
"task": 0,
"time_created": "2026-07-22 01:49:20.176Z",
"version": 0
},
"event_data": {
"Buffer": "0x2D0FA61C370",
"Connection": "0x2D0FA7C6940",
"CredHandleHigh": 80331,
"CredHandleLow": 3096573701856,
"Data": "170303005200000000000000015524E84E7136C6281C896F21A63586874785FBFE7305BF160BD4CFD195617A58EF033125D3C54807714EC5DB493FFA8AAFF11E1D50CC69BAAE00B314F650CC11948670CD948FCCCDB243",
"DataChunks": "0x2D090A98CD0",
"Flags": 0,
"Index": 0,
"Length": 87,
"SslIOContext": "0x2D0FA271730"
},
"message": ""
}
Event ID 710: Connection: SSL Queue Send Entity (SSLIOContext SslIOContext) (DataChunks: DataChunks).
#Description
Connection: SSL Queue Send Entity (SSLIOContext SslIOContext) (DataChunks: DataChunks) (RequestDisconnect? RequestDisconnect).
Message #
Fields #
| Name | Description |
|---|---|
Connection Pointer | |
SslIOContext Pointer | |
DataChunks Pointer | |
RequestDisconnect Boolean | |
Error UInt32 |
Example Event #
{
"system": {
"channel": "Microsoft-Windows-WebIO/Diagnostic",
"computer": "10.2.10.21",
"correlation": {},
"event_id": 710,
"event_record_id": 0,
"event_source_name": "",
"execution": {
"process_id": 9228,
"thread_id": 8044
},
"guid": "",
"keywords": 0,
"level": 4,
"opcode": 1,
"provider": "Microsoft-Windows-WebIO",
"security": {
"user_id": ""
},
"task": 0,
"time_created": "2026-07-22 01:49:20.174Z",
"version": 0
},
"event_data": {
"Connection": "0x2D0FA7C6940",
"DataChunks": "0x2D090AD6430",
"Error": 0,
"RequestDisconnect": false,
"SslIOContext": "0x2D0FA271730"
},
"message": ""
}
Event ID 711: Connection: SSL Send Entity Complete (SSLIOContext: SslIOContext) (Error: Error) (DataChunks: DataChunks).
#Description
Connection: SSL Send Entity Complete (SSLIOContext: SslIOContext) (Error: Error) (DataChunks: DataChunks) (RequestDisconnect? RequestDisconnect).
Message #
Fields #
| Name | Description |
|---|---|
Connection Pointer | |
SslIOContext Pointer | |
DataChunks Pointer | |
RequestDisconnect Boolean | |
Error UInt32 |
Example Event #
{
"system": {
"channel": "Microsoft-Windows-WebIO/Diagnostic",
"computer": "10.2.10.21",
"correlation": {},
"event_id": 711,
"event_record_id": 0,
"event_source_name": "",
"execution": {
"process_id": 9228,
"thread_id": 13156
},
"guid": "",
"keywords": 0,
"level": 4,
"opcode": 2,
"provider": "Microsoft-Windows-WebIO",
"security": {
"user_id": ""
},
"task": 0,
"time_created": "2026-07-22 01:49:20.177Z",
"version": 0
},
"event_data": {
"Connection": "0x2D0FA7C6940",
"DataChunks": "0x2D090AD6430",
"Error": 0,
"RequestDisconnect": false,
"SslIOContext": "0x2D0FA271730"
},
"message": ""
}
Event ID 712: Connection: SSL Cert Validation - (Error: Error) Context Handle(ContextHandleHigh:ContextHandleLow) (IgnoredServerCertErrors IgnoredServerCertErrors) (CertErrors ServerCertErrors).
#Message #
Fields #
| Name | Description |
|---|---|
Connection Pointer | |
ContextHandleHigh UInt64 | |
ContextHandleLow UInt64 | |
IgnoredServerCertErrors UInt32 | |
ServerCertErrors UInt32 | |
Error UInt32 | |
Reason UInt32 |
Example Event #
{
"system": {
"channel": "Microsoft-Windows-WebIO/Diagnostic",
"computer": "10.2.10.21",
"correlation": {},
"event_id": 712,
"event_record_id": 0,
"event_source_name": "",
"execution": {
"process_id": 9228,
"thread_id": 13156
},
"guid": "",
"keywords": 0,
"level": 4,
"opcode": 2,
"provider": "Microsoft-Windows-WebIO",
"security": {
"user_id": ""
},
"task": 0,
"time_created": "2026-07-22 01:49:20.087Z",
"version": 0
},
"event_data": {
"Connection": "0x2D0FA7C6940",
"ContextHandleHigh": 80331,
"ContextHandleLow": 80331,
"Error": 0,
"IgnoredServerCertErrors": 0,
"Reason": 0,
"ServerCertErrors": 0
},
"message": ""
}
Event ID 713: Connection: SSL Cert Validation Failure - Reason (Error: Error) Context Handle(ContextHandleHigh:ContextHandleLow) (IgnoredServerCertErrors IgnoredServerCertErrors) (CertErrors ServerCertErrors).
#Event ID 720: Connection: SSL Queue Recv Entity Data Chunk (SSLIOContext SslIOContext) (DataChunks: DataChunks).
#Message #
Fields #
| Name | Description |
|---|---|
Connection Pointer | |
SslIOContext Pointer | |
DataChunks Pointer |
Example Event #
{
"system": {
"channel": "Microsoft-Windows-WebIO/Diagnostic",
"computer": "10.2.10.21",
"correlation": {},
"event_id": 720,
"event_record_id": 0,
"event_source_name": "",
"execution": {
"process_id": 4236,
"thread_id": 9976
},
"guid": "",
"keywords": 0,
"level": 4,
"opcode": 1,
"provider": "Microsoft-Windows-WebIO",
"security": {
"user_id": ""
},
"task": 0,
"time_created": "2026-07-22 01:49:00.190Z",
"version": 0
},
"event_data": {
"Connection": "0x1CE1368D240",
"DataChunks": "0x1CE13386CF8",
"SslIOContext": "0x1CE112C3350"
},
"message": ""
}
Event ID 721: Connection: SSL Filling Up Recv Entity Data Chunk (SSLIOContext: SslIOContext) (DataChunks: DataChunks) (PlainData PlainData[PlainDataLength]) (Information: Information).
#Message #
Fields #
| Name | Description |
|---|---|
Connection Pointer | |
SslIOContext Pointer | |
DataChunks Pointer | |
PlainData Pointer | |
PlainDataLength UInt32 | |
Information UInt32 | |
Error UInt32 |
Example Event #
{
"system": {
"channel": "Microsoft-Windows-WebIO/Diagnostic",
"computer": "10.2.10.21",
"correlation": {},
"event_id": 721,
"event_record_id": 0,
"event_source_name": "",
"execution": {
"process_id": 4236,
"thread_id": 9976
},
"guid": "",
"keywords": 0,
"level": 4,
"opcode": 2,
"provider": "Microsoft-Windows-WebIO",
"security": {
"user_id": ""
},
"task": 0,
"time_created": "2026-07-22 01:49:00.190Z",
"version": 0
},
"event_data": {
"Connection": "0x1CE1368D240",
"DataChunks": "0x1CE13386CF8",
"Error": 0,
"Information": 13,
"PlainData": "0x1CE1363D8BA",
"PlainDataLength": 0,
"SslIOContext": "0x1CE12689B20"
},
"message": ""
}
Event ID 722: Connection: SSL Decryption - Context Handle(ContextHandleHigh:ContextHandleLow) (Buffer Buffer[BufferLengthData/BufferLengthRemaining]) (PlainData PlainData[PlainDataLength]).
#Message #
Fields #
| Name | Description |
|---|---|
Connection Pointer | |
ContextHandleHigh UInt64 | |
ContextHandleLow UInt64 | |
Buffer Pointer | |
BufferLengthData UInt32 | |
BufferLengthRemaining UInt32 | |
PlainData Pointer | |
PlainDataLength UInt32 | |
SecStatus UInt32 | |
Error UInt32 |
Example Event #
{
"system": {
"channel": "Microsoft-Windows-WebIO/Diagnostic",
"computer": "10.2.10.21",
"correlation": {},
"event_id": 722,
"event_record_id": 0,
"event_source_name": "",
"execution": {
"process_id": 4236,
"thread_id": 9976
},
"guid": "",
"keywords": 0,
"level": 4,
"opcode": 1,
"provider": "Microsoft-Windows-WebIO",
"security": {
"user_id": ""
},
"task": 0,
"time_created": "2026-07-22 01:49:00.190Z",
"version": 0
},
"event_data": {
"Buffer": "0x1CE1363D8A0",
"BufferLengthData": 42,
"BufferLengthRemaining": 8150,
"Connection": "0x1CE1368D240",
"ContextHandleHigh": 80329,
"ContextHandleLow": 1984520088224,
"Error": 0,
"PlainData": "0x1CE1363D8B6",
"PlainDataLength": 0,
"SecStatus": 0
},
"message": ""
}
Event ID 723: Connection: SSL Decryption Complete (SecStatus SecStatus) (Error Error) Context Handle(ContextHandleHigh:ContextHandleLow) (Buffer Buffer[BufferLengthData/BufferLengthRemaining]) (PlainData PlainDa...
#Description
Connection: SSL Decryption Complete (SecStatus SecStatus) (Error Error) Context Handle(ContextHandleHigh:ContextHandleLow) (Buffer Buffer[BufferLengthData/BufferLengthRemaining]) (PlainData PlainData[PlainDataLength]).
Message #
Fields #
| Name | Description |
|---|---|
Connection Pointer | |
ContextHandleHigh UInt64 | |
ContextHandleLow UInt64 | |
Buffer Pointer | |
BufferLengthData UInt32 | |
BufferLengthRemaining UInt32 | |
PlainData Pointer | |
PlainDataLength UInt32 | |
SecStatus UInt32 | |
Error UInt32 |
Example Event #
{
"system": {
"channel": "Microsoft-Windows-WebIO/Diagnostic",
"computer": "10.2.10.21",
"correlation": {},
"event_id": 723,
"event_record_id": 0,
"event_source_name": "",
"execution": {
"process_id": 4236,
"thread_id": 9976
},
"guid": "",
"keywords": 0,
"level": 4,
"opcode": 2,
"provider": "Microsoft-Windows-WebIO",
"security": {
"user_id": ""
},
"task": 0,
"time_created": "2026-07-22 01:49:00.190Z",
"version": 0
},
"event_data": {
"Buffer": "0x1CE1363D8A0",
"BufferLengthData": 0,
"BufferLengthRemaining": 8150,
"Connection": "0x1CE1368D240",
"ContextHandleHigh": 80329,
"ContextHandleLow": 1984520088224,
"Error": 0,
"PlainData": "0x1CE1363D8AD",
"PlainDataLength": 13,
"SecStatus": 0
},
"message": ""
}
Event ID 724: Connection: SSL Receive Buffer Posting Receive (DataChunk DataChunks) (Buffer Buffer[Consumed/Available]).
#Message #
Fields #
| Name | Description |
|---|---|
Connection Pointer | |
DataChunks Pointer | |
Buffer Pointer | |
Consumed UInt32 | |
Available UInt32 | |
Information UInt32 | |
Error UInt32 |
Example Event #
{
"system": {
"channel": "Microsoft-Windows-WebIO/Diagnostic",
"computer": "10.2.10.21",
"correlation": {},
"event_id": 724,
"event_record_id": 0,
"event_source_name": "",
"execution": {
"process_id": 4236,
"thread_id": 9976
},
"guid": "",
"keywords": 0,
"level": 4,
"opcode": 1,
"provider": "Microsoft-Windows-WebIO",
"security": {
"user_id": ""
},
"task": 0,
"time_created": "2026-07-22 01:49:00.190Z",
"version": 0
},
"event_data": {
"Available": 8192,
"Buffer": "0x1CE1363D8A0",
"Connection": "0x1CE1368D240",
"Consumed": 0,
"DataChunks": "0x1CE1368DCC8",
"Error": 0,
"Information": 0
},
"message": ""
}
Event ID 725: Connection: SSL Receive Buffer Receive Complete (DataChunk DataChunks) (Error Error) (Information Information) (Buffer Buffer[Consumed/Available]).
#Message #
Fields #
| Name | Description |
|---|---|
Connection Pointer | |
DataChunks Pointer | |
Buffer Pointer | |
Consumed UInt32 | |
Available UInt32 | |
Information UInt32 | |
Error UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-WebIO",
"guid": "{50B3E73C-9370-461D-BB9F-26F32D68887D}",
"event_source_name": "",
"event_id": 725,
"version": 0,
"level": 5,
"task": 430,
"opcode": 2,
"keywords": "0x0000000200000000",
"time_created": "2026-06-02T04:01:52.944+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{30000002-0007-FE00-80D9-0A91FC2DA028}"
},
"execution": {
"process_id": 11772,
"thread_id": 3448
},
"channel": "ETW Trace",
"computer": "JD-DC01-2022",
"security": {
"user_id": ""
}
},
"event_data": {
"Available": 16384,
"Buffer": "0x23E9106FE40",
"Connection": "0x23E900EFC70",
"Consumed": 0,
"DataChunks": "0x23E900F06E0",
"Error": 995,
"Information": 0
},
"message": "Task.SSLConnectionBufferReceive"
}
Event ID 726: Connection: SSL Receive Buffer Details: (Buffer Buffer[BufferLengthData/BufferLengthRemaining]) Data: Data.
#Message #
Fields #
| Name | Description |
|---|---|
Connection Pointer | |
Buffer Pointer | |
BufferLengthData UInt32 | |
BufferLengthRemaining UInt32 | |
Data Binary | |
DummyWorkaroundVal Boolean |
Example Event #
{
"system": {
"channel": "Microsoft-Windows-WebIO/Diagnostic",
"computer": "10.2.10.21",
"correlation": {},
"event_id": 726,
"event_record_id": 0,
"event_source_name": "",
"execution": {
"process_id": 4236,
"thread_id": 9976
},
"guid": "",
"keywords": 0,
"level": 4,
"opcode": 0,
"provider": "Microsoft-Windows-WebIO",
"security": {
"user_id": ""
},
"task": 0,
"time_created": "2026-07-22 01:49:00.190Z",
"version": 0
},
"event_data": {
"Buffer": "0x1CE1363D8A0",
"BufferLengthData": 42,
"BufferLengthRemaining": 8150,
"Connection": "0x1CE1368D240",
"Data": "17030300250000000000000003B512528ADF965141B7CF76C0964F8D974DE82DD1FA25FE935F25178D25",
"DummyWorkaroundVal": false
},
"message": ""
}
Event ID 727: Connection: SSL Receive Buffer Posting Receive (Buffer OldBuffer) (NewBuffer: NewBuffer).
#Message #
Fields #
| Name | Description |
|---|---|
Connection Pointer | |
OldBuffer Pointer | |
NewBuffer Pointer |
Example Event #
{
"system": {
"channel": "Microsoft-Windows-WebIO/Diagnostic",
"computer": "10.2.10.21",
"correlation": {},
"event_id": 727,
"event_record_id": 0,
"event_source_name": "",
"execution": {
"process_id": 9228,
"thread_id": 13156
},
"guid": "",
"keywords": 0,
"level": 4,
"opcode": 15,
"provider": "Microsoft-Windows-WebIO",
"security": {
"user_id": ""
},
"task": 0,
"time_created": "2026-07-22 01:49:20.772Z",
"version": 0
},
"event_data": {
"Connection": "0x2D0FA7C6940",
"NewBuffer": "0x2D0918BB240",
"OldBuffer": "0x2D0FA2EE050"
},
"message": ""
}
Event ID 728: Connection: SSL AcquireCredentialsHandle - (EnabledProtocols EnabledProtocols) (ClientCert SSLClientCert) (EnableRevertToSelfClientCertificate EnableRevertToSelfClientCertificate).
#Message #
Fields #
| Name | Description |
|---|---|
Connection Pointer | |
EnabledProtocols UInt32 | |
SSLClientCert Pointer | |
EnableRevertToSelfClientCertificate UInt16 | |
CipherConfig UInt32 | |
CredHandleHigh UInt64 | |
CredHandleLow UInt64 | |
Result UInt32 |
Example Event #
{
"system": {
"channel": "Microsoft-Windows-WebIO/Diagnostic",
"computer": "10.2.10.21",
"correlation": {},
"event_id": 728,
"event_record_id": 0,
"event_source_name": "",
"execution": {
"process_id": 9228,
"thread_id": 13156
},
"guid": "",
"keywords": 0,
"level": 4,
"opcode": 1,
"provider": "Microsoft-Windows-WebIO",
"security": {
"user_id": ""
},
"task": 0,
"time_created": "2026-07-22 01:49:19.988Z",
"version": 0
},
"event_data": {
"CipherConfig": 0,
"Connection": "0x2D0FA7C6940",
"CredHandleHigh": 0,
"CredHandleLow": 0,
"EnableRevertToSelfClientCertificate": 0,
"EnabledProtocols": 2048,
"Result": 0,
"SSLClientCert": "0x0"
},
"message": ""
}
Event ID 729: Connection: SSL AcquireCredentialsHandle returned - (CredHandleLow) Credential Handle(CipherConfig:CredHandleHigh) (EnabledProtocols EnabledProtocols) (ClientCert SSLClientCert).
#Description
Connection: SSL AcquireCredentialsHandle returned - (CredHandleLow) Credential Handle(CipherConfig:CredHandleHigh) (EnabledProtocols EnabledProtocols) (ClientCert SSLClientCert) (EnableRevertToSelfClientCertificate EnableRevertToSelfClientCertificate).
Message #
Fields #
| Name | Description |
|---|---|
Connection Pointer | |
EnabledProtocols UInt32 | |
SSLClientCert Pointer | |
EnableRevertToSelfClientCertificate UInt16 | |
CipherConfig UInt32 | |
CredHandleHigh UInt64 | |
CredHandleLow UInt64 | |
Result UInt32 |
Example Event #
{
"system": {
"channel": "Microsoft-Windows-WebIO/Diagnostic",
"computer": "10.2.10.21",
"correlation": {},
"event_id": 729,
"event_record_id": 0,
"event_source_name": "",
"execution": {
"process_id": 9228,
"thread_id": 13156
},
"guid": "",
"keywords": 0,
"level": 4,
"opcode": 2,
"provider": "Microsoft-Windows-WebIO",
"security": {
"user_id": ""
},
"task": 0,
"time_created": "2026-07-22 01:49:19.989Z",
"version": 0
},
"event_data": {
"CipherConfig": 0,
"Connection": "0x2D0FA7C6940",
"CredHandleHigh": 80330,
"CredHandleLow": 3096573701856,
"EnableRevertToSelfClientCertificate": 0,
"EnabledProtocols": 2048,
"Result": 0,
"SSLClientCert": "0x0"
},
"message": ""
}
Event ID 730: Connection: SSL AcquireCredentialsHandle failed - (CredHandleLow) (EnabledProtocols EnabledProtocols) (ClientCert SSLClientCert) (EnableRevertToSelfClientCertificate EnableRevertToSelfClientCertifi...
#Description
Connection: SSL AcquireCredentialsHandle failed - (CredHandleLow) (EnabledProtocols EnabledProtocols) (ClientCert SSLClientCert) (EnableRevertToSelfClientCertificate EnableRevertToSelfClientCertificate).
Message #
Fields #
| Name | Description |
|---|---|
Connection Pointer | |
EnabledProtocols UInt32 | |
SSLClientCert Pointer | |
EnableRevertToSelfClientCertificate UInt16 | |
CipherConfig UInt32 | |
CredHandleHigh UInt64 | |
CredHandleLow UInt64 | |
Result UInt32 |
Event ID 731: Failed to create HTTP/3 API session due to TLS 1.
#Event ID 900: ProtocolObject: WebCompleteProtocolUpgrade completed successfully.
#Description
ProtocolObject: WebCompleteProtocolUpgrade completed successfully. (Handle ProtocolHandle) (Request Request[RequestHandle]) (Session Session[SessionHandle]).
Message #
Fields #
| Name | Description |
|---|---|
ProtocolObject Pointer | |
ProtocolHandle UInt64 | |
Request Pointer | |
RequestHandle UInt64 | |
Session Pointer | |
SessionHandle UInt64 | |
Error UInt32 |
Event ID 901: ProtocolObject: WebCompleteProtocolUpgrade failed with error: Error.
#Description
ProtocolObject: WebCompleteProtocolUpgrade failed with error: Error. (Handle ProtocolHandle) (Request Request[RequestHandle]) (Session Session[SessionHandle]).
Message #
Fields #
| Name | Description |
|---|---|
ProtocolObject Pointer | |
ProtocolHandle UInt64 | |
Request Pointer | |
RequestHandle UInt64 | |
Session Pointer | |
SessionHandle UInt64 | |
Error UInt32 |
Event ID 902: Request: WebProtocolCancelHandle (Handle: RequestHandle).
#Event ID 903: Request: WebProtocolCancelHandle Complete (Error: Flags) (Handle: RequestHandle).
#Event ID 904: ApiObject: WebCloseProtocolHandle called (Handle ApiHandle).
#Event ID 905: ApiObject: WebCloseProtocolHandle completed (Error Error) (Handle ApiHandle).
#Event ID 906: Request: Set Protocol Option Option (Handle RequestHandle) (Error Error) (Length Length) (Value Value).
#Event ID 907: Request: WebProtocolSendData (Handle: RequestHandle) (Flags: Flags) (DataChunks DataChunks [DataChunkCount]) CompletionContext (CompletionContext).
#Event ID 908: Request: WebProtocolSendData Inline Completion (Handle: RequestHandle) (Error: Error) (Flags: Flags) (DataChunks DataChunks [DataChunkCount]) CompletionContext (CompletionContext).
#Event ID 909: ProtocolObject: Completing WebProtocolSendData (Handle: Handle) (Error: Context) CompletionContext (Error).
#Event ID 910: ProtocolObject: Completing WebProtocolSendData Complete (Handle: Handle) (Error: Context) CompletionContext (Error).
#Event ID 911: Request: WebProtocolReceiveData (Handle: RequestHandle) (Flags: Flags) (DataChunks DataChunks [DataChunkCount]) CompletionContext (CompletionContext).
#Event ID 912: Request: WebProtocolReceiveData Inline Completion (Handle: RequestHandle) (Error: Error) (Flags: Flags) (DataChunks DataChunks [DataChunkCount]) CompletionContext (CompletionContext).
#Event ID 913: ProtocolObject: Completing WebProtocolReceiveData (Handle: Handle) (Error: Context) CompletionContext (Error).
#Event ID 914: ProtocolObject: Completing WebProtocolReceiveData Complete (Handle: Handle) (Error: Context) CompletionContext (Error).
#Event ID 2100: Context: =====Request Initialize===================.
#Message #
Fields #
| Name | Description |
|---|---|
Context Pointer |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-WebIO",
"guid": "{50b3e73c-9370-461d-bb9f-26f32d68887d}",
"event_source_name": "",
"event_id": 2100,
"version": 0,
"level": 4,
"task": 901,
"opcode": 0,
"keywords": "0x8000000000000000",
"time_created": "2026-07-19T03:58:54.638443700+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "8B457A00-008D-0000-BC32-EC1F007A458B"
},
"execution": {
"process_id": 12988,
"thread_id": 8172
},
"channel": "Microsoft-Windows-WebIO/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Context": "0x1858B460F50"
},
"message": "0x1858B460F50: =====Request Initialize==================="
}
Event ID 2101: Context: =====Query Endpoints======================.
#Message #
Fields #
| Name | Description |
|---|---|
Context Pointer |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-WebIO",
"guid": "{50b3e73c-9370-461d-bb9f-26f32d68887d}",
"event_source_name": "",
"event_id": 2101,
"version": 0,
"level": 4,
"task": 901,
"opcode": 0,
"keywords": "0x8000000000000000",
"time_created": "2026-07-19T03:58:54.638963700+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "30000002-0006-FC00-500F-468BBC32EC1F"
},
"execution": {
"process_id": 12988,
"thread_id": 8172
},
"channel": "Microsoft-Windows-WebIO/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Context": "0x1858B460F50"
},
"message": "0x1858B460F50: =====Query Endpoints======================"
}
Event ID 2102: Context: =====Waiting For Available Connection=====.
#Message #
Fields #
| Name | Description |
|---|---|
Context Pointer |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-WebIO",
"guid": "{50b3e73c-9370-461d-bb9f-26f32d68887d}",
"event_source_name": "",
"event_id": 2102,
"version": 0,
"level": 4,
"task": 901,
"opcode": 0,
"keywords": "0x8000000000000000",
"time_created": "2026-07-19T03:58:54.639056600+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "30000002-0006-FC00-500F-468BBC32EC1F"
},
"execution": {
"process_id": 12988,
"thread_id": 8172
},
"channel": "Microsoft-Windows-WebIO/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Context": "0x1858B460F50"
},
"message": "0x1858B460F50: =====Waiting For Available Connection====="
}
Event ID 2111: Context: =====Request Connect======================.
#Message #
Fields #
| Name | Description |
|---|---|
Context Pointer |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-WebIO",
"guid": "{50b3e73c-9370-461d-bb9f-26f32d68887d}",
"event_source_name": "",
"event_id": 2111,
"version": 0,
"level": 4,
"task": 901,
"opcode": 0,
"keywords": "0x8000000000000000",
"time_created": "2026-07-19T03:58:54.639114100+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "30000002-0006-FC00-500F-468BBC32EC1F"
},
"execution": {
"process_id": 12988,
"thread_id": 8172
},
"channel": "Microsoft-Windows-WebIO/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Context": "0x1858B460F50"
},
"message": "0x1858B460F50: =====Request Connect======================"
}
Event ID 2112: Context: =====Name Resolution======================.
#Message #
Fields #
| Name | Description |
|---|---|
Context Pointer |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-WebIO",
"guid": "{50b3e73c-9370-461d-bb9f-26f32d68887d}",
"event_source_name": "",
"event_id": 2112,
"version": 0,
"level": 4,
"task": 901,
"opcode": 0,
"keywords": "0x8000000000000000",
"time_created": "2026-07-19T03:58:54.639131300+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "30000002-0006-FC00-500F-468BBC32EC1F"
},
"execution": {
"process_id": 12988,
"thread_id": 8172
},
"channel": "Microsoft-Windows-WebIO/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Context": "0x1858D0863A0"
},
"message": "0x1858D0863A0: =====Name Resolution======================"
}
Event ID 2113: Context: =====TCP Connect==========================.
#Message #
Fields #
| Name | Description |
|---|---|
Context Pointer |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-WebIO",
"guid": "{50b3e73c-9370-461d-bb9f-26f32d68887d}",
"event_source_name": "",
"event_id": 2113,
"version": 0,
"level": 4,
"task": 901,
"opcode": 0,
"keywords": "0x8000000000000000",
"time_created": "2026-07-19T03:58:54.639266100+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "30000002-0006-FC00-500F-468BBC32EC1F"
},
"execution": {
"process_id": 12988,
"thread_id": 8172
},
"channel": "Microsoft-Windows-WebIO/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Context": "0x1858D0863A0"
},
"message": "0x1858D0863A0: =====TCP Connect=========================="
}
Event ID 2114: Context: =====SSL Negotiation======================.
#Message #
Fields #
| Name | Description |
|---|---|
Context Pointer |
Example Event #
{
"system": {
"channel": "Microsoft-Windows-WebIO/Diagnostic",
"computer": "10.2.10.21",
"correlation": {},
"event_id": 2114,
"event_record_id": 0,
"event_source_name": "",
"execution": {
"process_id": 9228,
"thread_id": 13156
},
"guid": "",
"keywords": 0,
"level": 4,
"opcode": 0,
"provider": "Microsoft-Windows-WebIO",
"security": {
"user_id": ""
},
"task": 0,
"time_created": "2026-07-22 01:49:19.988Z",
"version": 0
},
"event_data": {
"Context": "0x2D0FA7C6940"
},
"message": ""
}
Event ID 2120: Context: =====Generate Headers=====================.
#Message #
Fields #
| Name | Description |
|---|---|
Context Pointer |
Example Event #
{
"system": {
"channel": "Microsoft-Windows-WebIO/Diagnostic",
"computer": "10.2.10.21",
"correlation": {},
"event_id": 2120,
"event_record_id": 0,
"event_source_name": "",
"execution": {
"process_id": 9228,
"thread_id": 13156
},
"guid": "",
"keywords": 0,
"level": 4,
"opcode": 0,
"provider": "Microsoft-Windows-WebIO",
"security": {
"user_id": ""
},
"task": 0,
"time_created": "2026-07-22 01:49:20.176Z",
"version": 0
},
"event_data": {
"Context": "0x2D09186A540"
},
"message": ""
}
Event ID 2121: Context: =====Send Headers=========================.
#Message #
Fields #
| Name | Description |
|---|---|
Context Pointer |
Example Event #
{
"system": {
"channel": "Microsoft-Windows-WebIO/Diagnostic",
"computer": "10.2.10.21",
"correlation": {},
"event_id": 2121,
"event_record_id": 0,
"event_source_name": "",
"execution": {
"process_id": 9228,
"thread_id": 13156
},
"guid": "",
"keywords": 0,
"level": 4,
"opcode": 0,
"provider": "Microsoft-Windows-WebIO",
"security": {
"user_id": ""
},
"task": 0,
"time_created": "2026-07-22 01:49:20.176Z",
"version": 0
},
"event_data": {
"Context": "0x2D09186A540"
},
"message": ""
}
Event ID 2122: Context: =====Send Entity==========================.
#Message #
Fields #
| Name | Description |
|---|---|
Context Pointer |
Example Event #
{
"system": {
"channel": "Microsoft-Windows-WebIO/Diagnostic",
"computer": "10.2.10.21",
"correlation": {},
"event_id": 2122,
"event_record_id": 0,
"event_source_name": "",
"execution": {
"process_id": 9228,
"thread_id": 8892
},
"guid": "",
"keywords": 0,
"level": 4,
"opcode": 0,
"provider": "Microsoft-Windows-WebIO",
"security": {
"user_id": ""
},
"task": 0,
"time_created": "2026-07-22 01:49:20.177Z",
"version": 0
},
"event_data": {
"Context": "0x2D09186A540"
},
"message": ""
}
Event ID 2123: Context: =====Send Complete========================.
#Message #
Fields #
| Name | Description |
|---|---|
Context Pointer |
Example Event #
{
"system": {
"channel": "Microsoft-Windows-WebIO/Diagnostic",
"computer": "10.2.10.21",
"correlation": {},
"event_id": 2123,
"event_record_id": 0,
"event_source_name": "",
"execution": {
"process_id": 9228,
"thread_id": 13156
},
"guid": "",
"keywords": 0,
"level": 4,
"opcode": 0,
"provider": "Microsoft-Windows-WebIO",
"security": {
"user_id": ""
},
"task": 0,
"time_created": "2026-07-22 01:49:20.178Z",
"version": 0
},
"event_data": {
"Context": "0x2D09186A540"
},
"message": ""
}
Event ID 2130: Context: =====Receive Headers======================.
#Message #
Fields #
| Name | Description |
|---|---|
Context Pointer |
Example Event #
{
"system": {
"channel": "Microsoft-Windows-WebIO/Diagnostic",
"computer": "10.2.10.21",
"correlation": {},
"event_id": 2130,
"event_record_id": 0,
"event_source_name": "",
"execution": {
"process_id": 4236,
"thread_id": 12820
},
"guid": "",
"keywords": 0,
"level": 4,
"opcode": 0,
"provider": "Microsoft-Windows-WebIO",
"security": {
"user_id": ""
},
"task": 0,
"time_created": "2026-07-22 01:49:03.235Z",
"version": 0
},
"event_data": {
"Context": "0x1CE0F728280"
},
"message": ""
}
Event ID 2131: Context: =====Receive Entity=======================.
#Message #
Fields #
| Name | Description |
|---|---|
Context Pointer |
Example Event #
{
"system": {
"channel": "Microsoft-Windows-WebIO/Diagnostic",
"computer": "10.2.10.21",
"correlation": {},
"event_id": 2131,
"event_record_id": 0,
"event_source_name": "",
"execution": {
"process_id": 4236,
"thread_id": 12820
},
"guid": "",
"keywords": 0,
"level": 4,
"opcode": 0,
"provider": "Microsoft-Windows-WebIO",
"security": {
"user_id": ""
},
"task": 0,
"time_created": "2026-07-22 01:49:03.235Z",
"version": 0
},
"event_data": {
"Context": "0x1CE0F728280"
},
"message": ""
}
Event ID 2132: Context: =====Receive Complete=====================.
#Message #
Fields #
| Name | Description |
|---|---|
Context Pointer |
Example Event #
{
"system": {
"channel": "Microsoft-Windows-WebIO/Diagnostic",
"computer": "10.2.10.21",
"correlation": {},
"event_id": 2132,
"event_record_id": 0,
"event_source_name": "",
"execution": {
"process_id": 4236,
"thread_id": 12820
},
"guid": "",
"keywords": 0,
"level": 4,
"opcode": 0,
"provider": "Microsoft-Windows-WebIO",
"security": {
"user_id": ""
},
"task": 0,
"time_created": "2026-07-22 01:49:03.236Z",
"version": 0
},
"event_data": {
"Context": "0x1CE0F728280"
},
"message": ""
}
Event ID 2140: Context: =====Request Restart======================.
#Event ID 2141: Context: =====Request Done=========================.
#Message #
Fields #
| Name | Description |
|---|---|
Context Pointer |
Example Event #
{
"system": {
"channel": "Microsoft-Windows-WebIO/Diagnostic",
"computer": "10.2.10.21",
"correlation": {},
"event_id": 2141,
"event_record_id": 0,
"event_source_name": "",
"execution": {
"process_id": 4236,
"thread_id": 12820
},
"guid": "",
"keywords": 0,
"level": 4,
"opcode": 0,
"provider": "Microsoft-Windows-WebIO",
"security": {
"user_id": ""
},
"task": 0,
"time_created": "2026-07-22 01:49:03.236Z",
"version": 0
},
"event_data": {
"Context": "0x1CE0F728280"
},
"message": ""
}
Event ID 59992: Restore Thread Token Token (Error: Error).
#Message #
Fields #
| Name | Description |
|---|---|
Token UInt64 | |
Error UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-WebIO",
"guid": "{50b3e73c-9370-461d-bb9f-26f32d68887d}",
"event_source_name": "",
"event_id": 59992,
"version": 0,
"level": 5,
"task": 431,
"opcode": 2,
"keywords": "0x8000000000000000",
"time_created": "2026-07-19T03:58:54.638481700+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "8B457A00-008D-0000-BC32-EC1F007A458B"
},
"execution": {
"process_id": 12988,
"thread_id": 8172
},
"channel": "Microsoft-Windows-WebIO/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Token": "0x6FC",
"Error": "0x0"
},
"message": "Restore Thread Token 0x6FC (Error: The operation completed successfully.)"
}
Event ID 59993: Set Thread Token Token (OldToken OldToken) (Error: Error).
#Message #
Fields #
| Name | Description |
|---|---|
Token UInt64 | |
OldToken UInt64 | |
Error UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-WebIO",
"guid": "{50b3e73c-9370-461d-bb9f-26f32d68887d}",
"event_source_name": "",
"event_id": 59993,
"version": 0,
"level": 5,
"task": 431,
"opcode": 1,
"keywords": "0x8000000000000000",
"time_created": "2026-07-19T03:58:54.638415200+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "20000001-0006-FD00-3056-4F8BBC32EC1F"
},
"execution": {
"process_id": 12988,
"thread_id": 8172
},
"channel": "Microsoft-Windows-WebIO/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Token": "0x828",
"OldToken": "0x6FC",
"Error": "0x0"
},
"message": "Set Thread Token 0x828 (OldToken 0x6FC) (Error: The operation completed successfully.)"
}
Event ID 59994: Get Thread Token Token (Error: Error) (SID: SID).
#Message #
Fields #
| Name | Description |
|---|---|
Token UInt64 | |
SID SID | |
Error UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-WebIO",
"guid": "{50b3e73c-9370-461d-bb9f-26f32d68887d}",
"event_source_name": "",
"event_id": 59994,
"version": 0,
"level": 5,
"task": 431,
"opcode": 13,
"keywords": "0x8000000000000000",
"time_created": "2026-07-19T03:58:54.638996200+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "30000002-0006-FC00-500F-468BBC32EC1F"
},
"execution": {
"process_id": 12988,
"thread_id": 8172
},
"channel": "Microsoft-Windows-WebIO/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Token": "0x824",
"SID": "S-1-5-21-1006758700-2167138679-1475694448-1105",
"Error": "0x0"
},
"message": "Get Thread Token 0x824 (Error: The operation completed successfully.) (SID: S-1-5-21-1006758700-2167138679-1475694448-1105)"
}
Event ID 59995: Canceling EtwQueueActionType Thread Action (Context: Context).
#Message #
Fields #
| Name | Description |
|---|---|
Context Pointer | |
EtwQueueActionType UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-WebIO",
"guid": "{50b3e73c-9370-461d-bb9f-26f32d68887d}",
"event_source_name": "",
"event_id": 59995,
"version": 0,
"level": 5,
"task": 433,
"opcode": 12,
"keywords": "0x8000000000000000",
"time_created": "2026-07-19T03:58:56.684640600+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "30000002-0006-FC00-500F-468BBC32EC1F"
},
"execution": {
"process_id": 12988,
"thread_id": 5876
},
"channel": "Microsoft-Windows-WebIO/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Context": "0x1858D1486C0",
"EtwQueueActionType": "1"
},
"message": "Canceling Timer Thread Action (Context: 0x1858D1486C0)"
}
Event ID 59996: Queue EtwQueueActionType Thread Action (Context: Context).
#Message #
Fields #
| Name | Description |
|---|---|
Context Pointer | |
EtwQueueActionType UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-WebIO",
"guid": "{50b3e73c-9370-461d-bb9f-26f32d68887d}",
"event_source_name": "",
"event_id": 59996,
"version": 0,
"level": 5,
"task": 433,
"opcode": 11,
"keywords": "0x8000000000000000",
"time_created": "2026-07-19T03:58:54.639820400+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "30000002-0006-FC00-500F-468BBC32EC1F"
},
"execution": {
"process_id": 12988,
"thread_id": 8172
},
"channel": "Microsoft-Windows-WebIO/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Context": "0x1858D1486C0",
"EtwQueueActionType": "1"
},
"message": "Queue Timer Thread Action (Context: 0x1858D1486C0)"
}
Event ID 59997: Stopping EtwQueueActionType Thread Action (Context: Context).
#Message #
Fields #
| Name | Description |
|---|---|
Context Pointer | |
EtwQueueActionType UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-WebIO",
"guid": "{50B3E73C-9370-461D-BB9F-26F32D68887D}",
"event_source_name": "",
"event_id": 59997,
"version": 0,
"level": 5,
"task": 433,
"opcode": 2,
"keywords": "0x0000000000000000",
"time_created": "2026-06-02T04:01:52.944+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{30000002-0007-FE00-80D9-0A91FC2DA028}"
},
"execution": {
"process_id": 11772,
"thread_id": 3448
},
"channel": "ETW Trace",
"computer": "JD-DC01-2022",
"security": {
"user_id": ""
}
},
"event_data": {
"Context": "0x23E9009F9B0",
"EtwQueueActionType": 3
},
"message": "Task.ThreadAction"
}
Event ID 59998: Starting EtwQueueActionType Thread Action (Context: Context).
#Message #
Fields #
| Name | Description |
|---|---|
Context Pointer | |
EtwQueueActionType UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-WebIO",
"guid": "{50B3E73C-9370-461D-BB9F-26F32D68887D}",
"event_source_name": "",
"event_id": 59998,
"version": 0,
"level": 5,
"task": 433,
"opcode": 1,
"keywords": "0x0000000000000000",
"time_created": "2026-06-02T04:01:52.944+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{30000002-0007-FE00-80D9-0A91FC2DA028}"
},
"execution": {
"process_id": 11772,
"thread_id": 3448
},
"channel": "ETW Trace",
"computer": "JD-DC01-2022",
"security": {
"user_id": ""
}
},
"event_data": {
"Context": "0x23E9009F9B0",
"EtwQueueActionType": 3
},
"message": "Task.ThreadAction"
}
Event ID 59999: Message.
#Message #
Fields #
| Name | Description |
|---|---|
Length UInt16 | |
Message AnsiString |
Example Event #
{
"system": {
"channel": "Microsoft-Windows-WebIO/Diagnostic",
"computer": "10.2.10.21",
"correlation": {},
"event_id": 59999,
"event_record_id": 0,
"event_source_name": "",
"execution": {
"process_id": 9228,
"thread_id": 13156
},
"guid": "",
"keywords": 0,
"level": 4,
"opcode": 0,
"provider": "Microsoft-Windows-WebIO",
"security": {
"user_id": ""
},
"task": 0,
"time_created": "2026-07-22 01:49:20.174Z",
"version": 0
},
"event_data": {
"Length": 130,
"Message": "0x000002D09186A540: WebSetHttpRequestHeader returning 0 for WebHttpHeaderDelete on Header Name (<StructNULL>) Value (<StructNULL>)"
},
"message": ""
}
Provenance
ETW provider GUID {50B3E73C-9370-461D-BB9F-26F32D68887D}
Defined in webio.dll, which carries the event manifest.
- WS2022-20348.4893, sample captured from a live trace, binary version 10.0.20348.1, captured 2026-06-02 — Manifest XML pack, 1.9 MB
- WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02 — Manifest XML pack, 1.9 MB
- Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02 — Manifest XML pack, 2.0 MB
- JD-WIN11-22H2-1-native-20260719, sample captured from a live trace, binary version 10.0.22621.1, captured 2026-07-19
Native ETL capture of controlled WebIO, BITS, and local network error workloads; identifiers were sanitized in catalog examples.